Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 25.x JDK (dev)

CIS
linux/amd64
alpine 3.24
Tags:

25-jdk-alpine-dev, 25-jdk-alpine3.24-dev, 25.0-jdk-alpine-dev, 25.0-jdk-alpine3.24-dev, 25.0.4-jdk-alpine-dev, 25.0.4-jdk-alpine3.24-dev, 25.0.4.1-jdk-alpine-dev, 25.0.4.1-jdk-alpine3.24-dev

Index digest:

sha256:71f7cbcffe5f41b2e448c960423413841bb7cdae4758955ba70404be30ccc8dd

Manifest digest:

sha256:9854fb8dd3d0a7ece238c04316404f20aa8e8a923b36cb4220f5e41d9681a2b5

Size

122.34 MB

Last pushed

4 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Sep 2031

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:25-jdk-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:25-jdk-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:41f5461889c987d6f0d04e9be70b69450099ebbdae530f3e0a8dab57b1640ffa
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:5aa04203a8b7b242a56aeed35e4c9871b029bc1ad0991ed48c54e7c4aaa80980
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:6fb9ebc7af8b10319990cb1f70861c67ba80ce4a9d42b01f8cd4c9d1380d74c8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:b80782e90c7f8e26fccea1b1c32a61c5bcf6d3b1e92eb71080205cd0b75c4c6f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:ba2e492d1feb807743e669772254a329c939b60f5438fe399cbcd618dfbb6256
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:16cbb61160f04b7b4c98f3c67732a0bde99c4b7c1248d1cf9b4e3e05f980c11a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:9a2d52fa9b4524c580ea6f7a646d7f29d337961bf6c9e9fd09b7c8f4c3245cb5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:9bca998a413d2e48b4a808a823ce0759546053127e3a8af7d47fe81dfa6b0e33
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:861c81321cb3a3b29cfe4cf7e7d5e1cce14c2555bb031ddfc72951379c8d3d54
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:dbe9c533861721092f5103eb16ed8faf9d326bc22f0ccbfdae258021dd134218
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:7f8029e71f2bb7e939f3773ee2b82bde83626d3e5b33ea014bdeef4414959620
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:acd975c5f4a01bf24e63f47ce2299eee9ded898800c783eba0c26b8c962ed79e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:6caa39d0ebd8700b1a63450e05a0e3f497372a60cb6b5ed15b169a68b9509a49
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:e3c34e8c4c6f8a7dae61e0476aa5f9924a9f462f603be7f271bbb39ef68b7cdc