Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 17.x JDK (dev)

CIS
linux/amd64
alpine 3.24
Tags:

17-jdk-alpine-dev, 17-jdk-alpine3.24-dev, 17.0-jdk-alpine-dev, 17.0-jdk-alpine3.24-dev, 17.0.20-jdk-alpine-dev, 17.0.20-jdk-alpine3.24-dev, 17.0.20.1-jdk-alpine-dev, 17.0.20.1-jdk-alpine3.24-dev

Index digest:

sha256:5085de52a7e6133b979f44377ee8ee92de978845f4cc0bbb6f33fcb31b1340bf

Manifest digest:

sha256:6f8aeac20cb769707747c93b87c42104803fb594e0da2ab22aa6d2d97b4ef80d

Size

173.32 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:17-jdk-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:17-jdk-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:2afe8e0f4aa711841ec2a8d5a95519f394217c935743d4532d0cfdea8cf10e69
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:a3f3e9c99a730e10dc597bf3e516fd9a8393a43bbfa8560e44f5f7195349d8ed
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:7971d000ed9c11c91a49bbdee14783d8676141ce06e02db4de8810f4f934ceb3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:b03c6df70049c22e221e92fe41294b53bb9514638fae79fab790398d31d31f77
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:45bd375b6346a2ae4a9555fbb4710f09cd5c5ffc8ef289a91b810f3adeffad9b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:6cd9eeaf48f5b7fc78f1cd321076f7f4cd01e34689c2845551203660e11002ad
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:ee875f5a13c6248448326cbaff8bbe9d6bb964cf39b9517088133c48873dd174
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:e9e5c9d58d5c9cac478805585a17e507aec5bf1959deaff59a0bf78c01d5663b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:e07429a40c2628263bb80cff586ed8d483a54de8612e272702cd7cc2a858fb9e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:c09a5ce2866a9c6ac93f7c987b5be74624712f305bda39eadb60a3c19601e4ae
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:c8e377be8c9d06170a2501c101a0965e344a71bf5436a8c67c26a6649bdd1cf8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:96c0a08b775d0d63d3418f008e540d6952803b474375c71ec638e85784c7e8db
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:bbbd4bd82b41175f38a98bae6575b992e7ebbd74e3d900fb590a1d05a83e8da1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:fe81be474ff9ed079849b9bdad382d393e5dfd687c0423d14589a70b82ddbbee