Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 8.x JDK (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

8-jdk-alpine3.23-fips-dev, 8.504-jdk-alpine3.23-fips-dev, 8.504.01-jdk-alpine3.23-fips-dev

Index digest:

sha256:d6ef96e5e71fcafddad3e1710ddf752fe1b7d26c850f7c65a53d03ead71a6853

Manifest digest:

sha256:97530d941118a36e197126e7a005f25038da8360f2a612dbc87fc7a9f723eb10

Size

101.79 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:8-jdk-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:8-jdk-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:3145f685c2c7acdfac52d1b158f14570c193efc0548b8a633b12a0d454d41ccb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:45b816ba1b8ec116997c55f743162ca2b7b66fc352d72ed8be681123827d10db
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/eclipse-temurin@sha256:6efe3e5795ba24c8b2fcb516810e40e17d9a3aae67fbdf084586d98a4abe6135
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:9f740c696d05b0562d23e73759f9a555e2b73df990607c7cba654bdc997b3d21
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/eclipse-temurin@sha256:207d7c79299e21663dc274d64e5942cc791d12e6bc6c4fefc3efee786ec6c332
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:bc9606ec47103ad4b332bd153fe3bb80a4c08edac8dca167d6d00600a10d6f47
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:a271a2af1a0cfc8ecf3dff0f169baa04c1b95f8fa65e8a3efaf2a09749c62124
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:87b17702242c76b79b9c51df1bc010c6d8cd66c161d99ddfdd77bf0ea3b0c74c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:2264136f9beb60d95528b6571c0e2d11fed5407cb4e1171d3fb53e086a8d5083
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:bcc21d77d907885d729caed5bf45536541bdefdf7a8fda978b8e25ede90158e4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:8ced125f64024ddc40bff08272782fc27eee44fab4a7aef351c3da787e691667
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:fe5428861f4d1affab7653882dd12b35d18c67c4d414676f798cb11ebf3b9bba
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:41538265dc58ace4c3816384dd9c90e8d943b46d2387158920e3382605b13aab
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:54529e8f92ae7812231a60bf7b41f2d464c88bb626b52f6547e821f344d8ecea
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:5a8c2a1a73863ceffe9409333454606700745eac2b8d0607c6ddd8c27e77e64b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:a92e47953885417c5ad69d6da15f925840eaf699f9e0f32a2fa741256b726ce2