Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 17.x JDK (dev)

CIS
linux/amd64
alpine 3.23
Tags:

17-jdk-alpine3.23-dev, 17.0-jdk-alpine3.23-dev, 17.0.20-jdk-alpine3.23-dev, 17.0.20.1-jdk-alpine3.23-dev

Index digest:

sha256:9a0884a35ddf696d0d7f0776ca8540036af94e056a4d537c0a73338428d3535d

Manifest digest:

sha256:777d5ded50216f48cbf14b072e4efae2ec9676f2eb7781703d62bc506f72f1d1

Size

173.29 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:17-jdk-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:17-jdk-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:bb6b9389fd6599cc62c4225a9047e121eaa2cd65bfa46b57fab9ecc5f00a0cfe
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:1286df32096faaec3c59e2154351eccfc78f686bf79247ffd251804148b463b4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:7e728c2f2956fcfab224ff9ede8a3944d31d7738453b4eaa6f5d69c6062f69e1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:0d61423ebf1fff4ea112b3fd35885bca09d9aa49c5c011b5ea4c2ec508a7e6c1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:017084a566632c4b679838aa21d84f56d5f548b6c4417e721c8957e0255ee7c1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:4153452231e013c62634d0ec1ed3e23f122d5f7502b2b6a6528d3e8e4782de87
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:cfd23106f0878dc5d9aac8488029244898af2cda8963800ffb2b52c8810984ae
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:53c703d80b88e66300b1988327df4dc268966861a3a59bb7018d0170c9cc48a1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:681973f887d4259d029e75f8b75064773273387802325c166af0a26d56587d62
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:f8860c170318f810bdd25bd18ef0d5cdc10a94ed1ca0e5a32c1db9d29ee72cea
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:592d931df6c8cbf6b4ad6408a62a2d349fa70e774fd455ad940ec167282b1266
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:9d2811806ee8d2d20680e21e24749aa76a0164e0d66f6e50282577024d585d60
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:353bbffc1c462ce95e64c3f1fc761d862d124539b73201afab72f480a09aa18d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:70cce9384f074706333eeab7a3122c959bdc2c46004fdb4b341a186aaed4c607