Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 8.x JDK (dev)

CIS
linux/amd64
alpine 3.24
Tags:

8-jdk-alpine-dev, 8-jdk-alpine3.24-dev, 8.504-jdk-alpine-dev, 8.504-jdk-alpine3.24-dev, 8.504.01-jdk-alpine-dev, 8.504.01-jdk-alpine3.24-dev

Index digest:

sha256:426cedda405fea6a8c7142ce75093628a80278ddf412f6140386f28ea1dfce0c

Manifest digest:

sha256:3b76d107d5890abefdff8fe63a05d7c699cab81e6621a7228d477a7df0502aa8

Size

91.94 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:8-jdk-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:8-jdk-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:c1673710f65936f31121c8b1a9a737b5858be883bae43ebc372bc5a04527c6c2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:154b912a1b6fad71bd437ecded36195e9c161603adef9db45125afcb2ee3df1a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:be88a00f0fce0bb6e425951588906350a6228d0aa8834cfd5b38b0fb3dac71be
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:067378e9f45c9f2057afaa0484ef0ef37a7c7cefca56bacc5aa6d7bbcacecea4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:4bedab9e792651356d9907345ac1cc470c96d8d3910b691111a87d6fdfd38483
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:dc2f346aff043f195b883dcf033c603a32f4eb9a488c3473830384ece7fe2bb4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:6ed78e0a8167c95059c409fa9f6c936d80c35b031ad282acb313e007c6fb52d6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:dc7716317cecc4e9425f9885588562d022a53e1330818f63a0eb910156e6af37
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:dfd7733c1d5351061c928e37f5f8442285e4e5c2f67affd8881fa499fbe8f249
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:bfd2b877c6b5d4e89fa5564c4681faa27d83ae7757e874ddd8783549e37cba0d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:33cedce80b32736b53deeb285ba79160d8c0b12dc52a8c13fde0766d91ee8765
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:3ca8205d376865675aadc13407b93f28e760959f2e4d4f165c2e99b21c06b94f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:62993dc5a4962abe526abd6d1133d8d70a8649fea853465fcaac74c992aeae9f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:2d807bb62a34ba8daf9768e56bf2166eaf91a0d53fae390cb0ddc9efd3657d1a