Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 25.x JDK (dev)

CIS
linux/amd64
alpine 3.24
Tags:

25-jdk-alpine-dev, 25-jdk-alpine3.24-dev, 25.0-jdk-alpine-dev, 25.0-jdk-alpine3.24-dev, 25.0.4-jdk-alpine-dev, 25.0.4-jdk-alpine3.24-dev, 25.0.4.7-jdk-alpine-dev, 25.0.4.7-jdk-alpine3.24-dev

Index digest:

sha256:17c1b56218efe96f7a9044d2711280ce197242304a7c892660cd5676c3ba0d7f

Manifest digest:

sha256:8aeedadce40cef9510cb90d3a1b6116a6838c4e7417d0c5e9d83f9f639e3d2f3

Size

122.35 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Sep 2031

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:25-jdk-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:25-jdk-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:77fcc2a7675153084c8f9d999aa427e0212f911d5749e31d7c20327ed5c34e5c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:7eb5515811b9cb28c41a65d0229dd45c42bb12562873a6d1badd66e59e3ee4ac
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:d2bded6dbdb3b5a952779078e1546af28c739501de1d50d252170cfa64b3893e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:40fe466dbb5a340b20723d2b68110f7789a3b6b16cdb58fef2b04e135255f488
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:56c87462573c95358ced98412d8e31dbc75982e6ce8cf06d74218b533f2be745
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:4f9c7f5a59cad6bba477f7ac0de35c2e5c60ac8b11d4ff4778f025c43c9e24f8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:92534b8d881d3969876792e72bcacf6bbb29769c076ea6034d815fb412eaa191
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:987d86c7dd384ed695665bea0d9554f99e9f76d0ba2465ee7ae8a6974c0599a8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:7f6a7120ed769ea60ad502ff476f2598f2ce772173b13fbb4d577f959c2788d3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:3ba000878e4c975dec9813b226dd3afc753f943699b7d7061fe9dec4142fe7ac
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:44a7966ade3e2b6a07e48d74bf2f4c7a4ba88c18c91ca76ea7353ace191cf10a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:f154dd1614533465fe7ed2dd91eeef0f10dd0af201b3190bdc5cb6cd5395a0f5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:af604680d6fd6fe3ae882bf478acc667016a02321c5375bdd8d49efce9fd9c6d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:6fbda0835708aaf792eda2f452f56dac9cdee900a5f67c18c78d1f325260c402