Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 11.x JDK (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

11-jdk-alpine-fips-dev, 11-jdk-alpine3.24-fips-dev, 11.0-jdk-alpine-fips-dev, 11.0-jdk-alpine3.24-fips-dev, 11.0.32-jdk-alpine-fips-dev, 11.0.32-jdk-alpine3.24-fips-dev, 11.0.32.1-jdk-alpine-fips-dev, 11.0.32.1-jdk-alpine3.24-fips-dev

Index digest:

sha256:25117a52d8d95cf79f13462b023f06a5a1a3ce5c94a2b25eaf25738b8b59588b

Manifest digest:

sha256:ed738deb0ef4bf4c6e56028c9cdeeb55c5bd9249349b7d8e7ec98c1d3f0cc2ea

Size

184.93 MB

Last pushed

4 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:11-jdk-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:11-jdk-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:b06f9e961d15fe25fc3445362626236c09a33961b881dd1b36bb0f81d84bae22
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:de20ca2bca007ca9a716911268d8dc0fded222e94ea926ac9c12acfa4468f98e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/eclipse-temurin@sha256:65aeae50ec06ef7c54398b66e0ad933e9a8e8661d6450f5407e0d48c2553a8f5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:86a026376d9421d7f522fca688dd43dc780913d9f7d1545a2ed7cea0bfc0cd5f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/eclipse-temurin@sha256:64eca50b9546b64e2ac147ae14da2a7cac5b3fe38a61f1d4ffd2c42efd6b3e2b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:9a888da9a4595ed0297cc4a724097934e51d60737333f109e70d27b333b90b81
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:430fecc70064faa31639c6a27d9a587a181be9d2187e0c8e6286582f7afbb0dc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:18fef80bebe193a0e9707bf8eaca5b1c63be34b52881923e2f211c1adb4d5156
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:4c3a6f9aa219ca15790a6d596d9700c2ab2c222aa6d7794f360cc41a98fada7a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:eb8c40de0629642d24bffeaea16f741167fd7bd27cb7df699134b29458414a68
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:c4c12a150a7807866356bffb0790c0b31b2eb53944b8f1362ea66307b306efe8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:871f3cb4ec100612e72ca4bc9aaddcda17c4b990a7c99b0ba700386169211981
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:fd16672868eca53dd996e0bb5d0486d813f4e5bade6e877bc050224b253a8bff
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:de79d623f664aa7983da8ccdcab3cc736dd5ed3621308a802290c79b179c833b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:5caf1066189edc522e22621da987187fbbc0c353bced22e757d7755137784cc0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:82daf68baee4833670f12a509bf1576ce15c8df51ed59b6eb5af66985e01e6c0