Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 17.x JDK (dev)

CIS
linux/amd64
alpine 3.23
Tags:

17-jdk-alpine3.23-dev, 17.0-jdk-alpine3.23-dev, 17.0.20-jdk-alpine3.23-dev, 17.0.20.1-jdk-alpine3.23-dev

Index digest:

sha256:e16ad2358ada2960e2b6bf0ef626e1a0ee0712bb252ab0d3cf01fb7b3283c367

Manifest digest:

sha256:f4e9661a93810a6e2f16ca5b07d2ebe2ebc3e3a301d02670bf5e3f9c14cfb8ce

Size

173.29 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:17-jdk-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:17-jdk-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:6f3b1646bbd13529fcc30ecc48b9dc17b5c358edcff04943fe3bc7eb071d4299
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:bae340cc1eeefe2f3f2ef46364b7f654843dac10a0f1a41263b0a184cb7e3c5f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:1b0af8e2d1655cf9f96155ae35e5479c3b6d0b5e536a60a9bb3e92cbef3c81b7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:bd07301caeea5e16a27d014b4f7f9dfc39335f6e847e0e0ed25028f884958572
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:3ef1e7cc83ccff0c8ca27b268e16afc3eed433b1657ae4fde93d7d0679fb8ada
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:7bffe50a1e76bea19e362d0b08eb7caaa2b54fdf57f85dbc3c81d03328480ea3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:373bd3a03d41c41fabd137feac1be77e5b8b92e52000bea513533cde9ea3e7b3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:9ed9d6efa38d13274f771f071bbeb4e26074d2f52d664c428bb7cf15c1c4c21d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:017a7e6f53afaa73b74faa4292c8b338041e1f72b2f4d3752db1465f46eab94a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:3581edf750ae924dffbc5039b8cd96393a48742e46fd620639d7e44c55a7891d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:593e2750308f020342c4e009dcbc4596f787d0961f64fecf0e744aa54c52ebb8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:4c12bda676fafc0ed1adb6a0b12048cb50dad0c493d9061c16f3c3b82d490f8f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:e72f3bc59bc355a144ac9b9f276ed3bb05003af7f3af64455fc1ca7f847f4302
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:126ff0cf846fef13e926465cf7a5e99e229d8a430956f7b6f986ef87ba1f1e58