Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 8.x JDK (dev)

CIS
linux/amd64
alpine 3.24
Tags:

8-jdk-alpine-dev, 8-jdk-alpine3.24-dev, 8.504-jdk-alpine-dev, 8.504-jdk-alpine3.24-dev, 8.504.01-jdk-alpine-dev, 8.504.01-jdk-alpine3.24-dev

Index digest:

sha256:b1a9f5b8c2b1de1bbc55c3d7bb03acc40c2102078a94fc8221cc1a7e3b0956ed

Manifest digest:

sha256:2d4f5a63eda880cdf627656b61ce75e55acc09895bc200755b33c784ebcc7d46

Size

91.94 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:8-jdk-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:8-jdk-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:2e9b3893d4acf8c64dd268cacd724c4d07b74f84e4761d4a875095023f950c8f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:f305c52cf82699d4d7a84c8d83453a72ebc3d2e34df6f289bdb61a7817434e5c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:fc5abb23a5bd518cac2e953fe068ef69cf8adce795faa9e17771a9bd28873b31
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:6a732110bf1ebef078a83a23c4ccc36ce96be491e7b198d3e136698284b5c3eb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:07aa618692f359e4a2d64f1033d3e38b395b517bd28479a17580c274d9280be9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:f86e894ee9b0f46791afdb6a78c758b0612a691a1c5fd639b8039b08df17db1f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:5371551e0151fbd224d7dea573787a5a28ff8aa00d5c3043a32ad6b49e49f9a9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:ed4218a4a312d1422c3c9372fd71bb976e4265db07a93683ec08b97d4ca602fa
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:ae3997961d1fb80949f55596c606465ca5002af488fccc69473255ac04595663
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:73f05781b6bea67fbd1dc6e8c65daafa0d1294dd663fcfa783de3c0a020d2dc0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:4499623391a3f0b14789a905cd90291dc83203b201a7db0ecd6329bfb1012047
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:827936ae7de2538409a7ed513a06714e4d116b6a4162280641103d452fc1fdfc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:5f492af2637c9682afc5ca781893df0f4b1e1f68fd7e2b4916fa3252dcf6fad8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:d08708f3c9d837409dff9806a6f317514eda9353457a4fcaebe899dcaf4d891e