Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 17.x JDK (dev)

CIS
linux/amd64
alpine 3.24
Tags:

17-jdk-alpine-dev, 17-jdk-alpine3.24-dev, 17.0-jdk-alpine-dev, 17.0-jdk-alpine3.24-dev, 17.0.20-jdk-alpine-dev, 17.0.20-jdk-alpine3.24-dev, 17.0.20.1-jdk-alpine-dev, 17.0.20.1-jdk-alpine3.24-dev

Index digest:

sha256:ad09dd6141b934b5bdec8964807cdd2eb02a2137340b774d712ff850bbbcddfa

Manifest digest:

sha256:77fbce26f512ebbe7ac2503c4adf46af7a33a88c41d4700c0219f7e49a7c6b99

Size

173.31 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:17-jdk-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:17-jdk-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:813be51d7668f703442c4241466504ca2d5224ea737d958cc74784a7c8732e91
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:9bba0a0bc8f088da4edcafca06274d523a2b6ab88e7d08663a0a444619e28700
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:ea1d42d136278820a53f3e4d4cfed60c0ba74415c4dd9c4cfa7c08074ef24751
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:c810d705b4f02f01bfb68693de30132fe62f6869091913bae48b2711bddf1800
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:131a0b2410ae2592e9ac74518056f902cac05e3d866db8fb245c514b1f685a4e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:1281e75f2fe5ab305cdd83ed4ecf7b1060f203fd5668c6fa53059b99e07e0a93
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:04bab4c7420214a06eb3cdcbcae6da4b00a8e3978cde31cff5ab67cd0f85d2c8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:bf5efb409fbc1e892a762cb72b76852823f37a2b629e239116d2a9a347df4521
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:5e8cf6235ac674c07f6d793336998c1cc305a1071623acb3125c4998f3bc8304
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:8cb7a95257ffc652e205958b893a96c17d4f3714f1a29932337787bf082bda2c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:4ae86bcf8325f7ac558c694bb17ab151e2c2ae59d07cf617822e56ed5e5e63db
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:ca2f0e3509b790607802f77226f50978587bce5bf1c5c6eba5551e4fe87f6b21
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:8a44147731f9d31c707f4f3a8b8e037b646a57f096f426e67c42a816afdf8d46
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:67fd4b3dccbf37ff607b28f88a4e312cf8c9d6ca0a37d04c82579eb931f3c831