Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 25.x JDK (dev)

CIS
linux/amd64
alpine 3.24
Tags:

25-jdk-alpine-dev, 25-jdk-alpine3.24-dev, 25.0-jdk-alpine-dev, 25.0-jdk-alpine3.24-dev, 25.0.4-jdk-alpine-dev, 25.0.4-jdk-alpine3.24-dev, 25.0.4.1-jdk-alpine-dev, 25.0.4.1-jdk-alpine3.24-dev

Index digest:

sha256:a8d4aa7af6baa8f7bb17f6e3a9e2750dbd14b724a17be5b875576f07fb256d15

Manifest digest:

sha256:a3a4249f74aacd6ccffe4a53bb32c232a958b9b3c09e976c9676d6480f1d05b2

Size

122.34 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Sep 2031

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:25-jdk-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:25-jdk-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:a84079b8c94083aecdb97827e5d9bf30f9e62c90d9d2999cd62c81a3293399ff
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:91bc1a50dbd3485bcba988181eb0a1a4d00eda89bf24109e5b9097c132dfad1b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:402dae7d72c00b7feb0b5dda56b9a2063978e73b060de4e9569a3479bb9c5000
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:7e4dcc1691430271543c2623dfddebab67ed4982bde99d6e477ec52ef2e3edab
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:d892985e68c21557ce3d9e00beeef4a279bf7a9af07d8439656d3d0b06c1866d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:904efce43f828e688ccd7f7f58eecc82101905fa0fce907bff3e8e9092d751dd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:ace81ab9f66f26bcdb11ec7c727b047726e4f3dd6d4f531bf020da47710f6412
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:43ca6a32920328398b1054a098ab7518d661cea7c424dba5f3377c545115ca22
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:4689247ac590daa7c780df5e2537844b3ff37857ab787c721bcde56d2b561951
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:280ce30960448d08a345d2aafdee96c5a0e8344efe69e8def0830acb5aaf97ce
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:7c7268ac55036650813d33a5bd0db0f1815a1be2820c40cf7d4404b06aab2ccb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:f693bee2f449d3e7a78c4b2c0b5341593423e87b36904b7a76c9aa08daacf5b9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:954fc2b27e364bd12023a28ef8921d09cf08c9d3036d63bfc142213935ab8be2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:f842c1ae97f1c7ea7985b1cb6e0c3a4e46e7c5bb4e3cdfb30992ceb9cde90ebd