Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 17.x JDK (dev)

CIS
linux/amd64
alpine 3.24
Tags:

17-jdk-alpine-dev, 17-jdk-alpine3.24-dev, 17.0-jdk-alpine-dev, 17.0-jdk-alpine3.24-dev, 17.0.20-jdk-alpine-dev, 17.0.20-jdk-alpine3.24-dev, 17.0.20.1-jdk-alpine-dev, 17.0.20.1-jdk-alpine3.24-dev

Index digest:

sha256:ef2cde5d52da0e92b3a810ac051f43d404dbd230eae7cf5bd72aba1c064ee9d3

Manifest digest:

sha256:9bd53a8e2d307a4587b9c2dbfa25c6047d6d40aea5b6b7494f58cd8f76a94eeb

Size

173.32 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:17-jdk-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:17-jdk-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:0026a52cc93fc685c4bb278e802ada4f159ea73ba0960cb377f2f077dddf6dcb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:09b91efedc527b2ad0e5678bb639aefbc9b50deb9a7735670d3e0c1fa61a80ee
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:7be8eb5899a81d2de5d5fd3c52ef2e3525ecbc640892db16b26648d40ea0ca0a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:d91a950a5565438814319f92dbd76c477c065ee1f9d1c477c435766f66fba971
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:404566b2eeae6338d8d299725ca6f526bae35f12c75aad22ad6a68f27d062ca0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:63d6d967fc5f3f82f8378840be96c55beef317835ddbfd4b2f75633b2751f1a8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:e283c55d047010d0a942860d86bc0ea605a4911596802a3ae1033cb2f68951bf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:75bfeb4e2293a00331be4cce62798934ce0ddefe92c1b9521aa27c919bb47996
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:11577e87cf26e2960b48b9b9c85e514188985aebb2cd7b62071e892f94c0d89e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:33754c947cc48cec43f70808f22ca63eef8ccb09329724e6454f67f23cf9f78a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:655a680c73349face5abcabd3210e3f3a8e6e86c3c9931dff33c2b2d4b94394c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:ebf3ab4c8832f31f4b6289f97bdb3d59e2599f736eefd5368d6b5565748dcef5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:a6a98111c386c35736f86d9b3945d01dc8539e12e20eecd42ee0bd1c121b08cb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:e6936d91cdc9a60b2e47b0b9960b83709de57e0824c6488f6f13726b23b616ab