Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 8.x JRE (dev)

CIS
linux/amd64
alpine 3.23
Tags:

8-alpine3.23-dev, 8.504-alpine3.23-dev, 8.504.01-alpine3.23-dev

Index digest:

sha256:5865e81c272f5468b94212fa16c89658a7bf027f7274197c3bc6cc7dde5490f2

Manifest digest:

sha256:f67302ef4bbf4c76e3a7b6bbe6a3f52aea4bbb7fedea80e5332a32b725266850

Size

38.60 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:8-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:8-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:95a7b677b38c1681e50da86340713eb925d110ef52d0813ab346f24c2f9aa176
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:8c7c8077d329f59e99bc4cc397b78a502f9b99e206f186e86b2c045a4e87081c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:288e6f3cc232c5133b4ac5f1e6960f2962eacee7488698b37080a80177608787
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:d8b320224a58b182b43e003ff4a0f7390bec60b147f16f77617b4fe03836575e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:82632cb73183a95bf5408f1952f26058513baf703945e83fe5a955d08e597df8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:7b92dce23fabf4d822b822d58fd4ec83526dd859fafc5412e34cbdf957a6aefb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:d65d0d98878f5a2b60078d92fa199e1171c1980d92f6f7a19327e0cf56c06db0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:625c92a081a53a1cdb20e81c0d365588f57872c8e84f4b2f70e02f6dbe0bcd1c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:0aa4dbcc7b7cad208549a709cb12eaf2a61332da720952a0602775195fef235c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:5d66cb130ee75623fc98c43d242c3a92fb9aab9ae48e5a1432ae3f2863464948
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:c2b886cf7dfcfc94224ffc7ecc4dd621389fa40dbf51ebce08c231d192682e05
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:8f096323d5b1d342467ac20a889ba691148637287689d3ac8a5a776c04c01596
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:626658f645ac76f6ec6508d04e692a76effdfb54518705f7ae36913047f8e763
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:b9edadfcef6b9272929bd74bf756c6819c3188a3ca1450fa984b635ae3a77066