Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 8.x JRE (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

8-alpine3.23-fips, 8.504-alpine3.23-fips, 8.504.01-alpine3.23-fips

Index digest:

sha256:4301cf5a01515c7fcbb0e97342b1fd03ff11428573dd0995a52735ba2e73d078

Manifest digest:

sha256:aa93dd808b8e6488cefa8a6685a8fbfa4d3b0ae740fa34e1987297b08362d50b

Size

47.63 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:8-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:8-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:9e23551aade773a92f70c6f81228e2149aaaa042e8cabfec28e57c6fb135090c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:fab0b6482959587d4f0313ccfe44617cb175b2a45d10f8746769b21883c95fc2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/eclipse-temurin@sha256:44b2880c78de2a59b4d33500d6f25459b7a9806d9da8f2e76f8d141d5fe9edba
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:d074709f74635a8c1e29057e88b86478edacb1b13290b82172b2bf51c9be12b0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/eclipse-temurin@sha256:5083e774661de73844fb2ab9a33a9279cb491dfa307ecdbd7fd07d44a5e07e2d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:d2e3e29632ed4595a42f610665ed737e21633d50c555cdbb46907f6e111eb0e9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:ca871e86f1b817c56469334f8a2b89ca6763cae76719f8fca5e467eebaabb51a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:930b0df002a97dd50871378a94a4a1ac23ce0b15731169dd5d2daa26415b855f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:f0f1869be817281abe78cdd44c5b858c0e6944d0912b9d83e7fe12e0d4ab44f8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:16d88a8125c11e337f922777c6df2842df37243fa729fa0ad07847dd3537adf5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:b2dc5cf561fcdddb323f699b9bb0b7a763181d1086619cf1890dbde26177ce88
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:8d20d2d55a0954278b17f661e4d61acf0f23a78b74326212d9ecdc5391458540
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:394ffc537d0ad38169083e65f88748c5518da237ba576ec617b5cf81b37a15ac
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:8a6d776ca0f1457ac5f682cc2bc07115f88d161268d2ab019cd9bd2780ad8332
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:f72732a003c22290a182ac52dcf790a4e788d5e989a42ae9236fe8e455d1fd26
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:b62f3689aedd67d7b14d4109b519b8f99985cc5e2d2c33b7684800958e54ac92