Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 8.x JRE (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips, 8-debian13-fips, 8-fips, 8u504-debian-fips, 8u504-debian13-fips, 8u504-fips, 8u504.b01-debian-fips, 8u504.b01-debian13-fips, 8u504.b01-fips

Index digest:

sha256:5e7907b01650f763b5b3b0ed1fd196c2e98fa0719a878b2a0ae916c0e476b07b

Manifest digest:

sha256:dfd274555829ac7566b25956936275ec1bb1c28dfd7efc2e87d134a66b8337bd

Size

58.59 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:8-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:8-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:56a7b26ed2ad702e06f7b9d275553230173a6d0a4cc44c8affc70df673c4b81f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:6398a374c777b06f304e345a68091c800d2ecba84de909fb3a8d00f12eaa91cb
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/eclipse-temurin@sha256:46a664ea4829a21496e90145d6327189cdb94ade24ab9643957f8b2bdea13ac0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:3206e72823bab6013d9cf5676efa305386ea07b38e50be4b663cc386c4a1f802
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/eclipse-temurin@sha256:fde6347a5effe4a1379b001f0052030ff83965eb0edbf417e3ffd7f6fe071377
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:301051e37fc841381e8e733afe2bb4bfa4b1220f287452d5e06f1ffd85d57ecd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/eclipse-temurin@sha256:f073ddee909b6b6a65b5179c0d2920e6f5db72f48a3ca6e1b5382ecd4ae66b7a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:3a7f9a33ffafbba55a3a2d3ab4cef1d819edc65197fc48e263840bc5efabb0ae
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:9e6a5eddfaefbd66a7490b9ed1c0a2a07b870998737683b44867486a1ae59746
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:d81cbdd2cfddb998b29b59f2b968f8611bd2b87572bdb8937c71de76220e826c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:cb6f150b3c14cc34813d4e8477e68177cef5d88b151befbe261ab1029a6d2399
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:fba657f41476d35ed540d3eb1ff8e1989ee8c507323f22d68796ca3b292de155
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:e73398a60a8c9c830a54a056d544beaae0736b2adc381dc2cf2a1d2126cd57d1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:0fc63fd621d5039c521c7961a0d60fe6f22ac3919704a27c4eeafa9c2aa791ab
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:7d1713d06e00143dc6fa7f5bb7e6be0832ab90744a2af33e297dc7e4301822b0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:e5ab4f73637bc9acf6c65c60e7a6b7488006c94d091f80f04070ed7513d7c1a7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:37b66af82702e7dd2d073f4d451bec16fddb8654d54d2b5a5a11e60b3792a0bf