Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 8.x JDK (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

8-jdk-alpine-fips-dev, 8-jdk-alpine3.24-fips-dev, 8.504-jdk-alpine-fips-dev, 8.504-jdk-alpine3.24-fips-dev, 8.504.01-jdk-alpine-fips-dev, 8.504.01-jdk-alpine3.24-fips-dev

Index digest:

sha256:0e2120c445815554c0351035eddb96e85250710ca8cba7469fa29fdc78be85a0

Manifest digest:

sha256:ae51b752b58131ff61c9f9f8f2c9361dc9e4799e5fb5bcaeaa87e1eea45658f4

Size

102.55 MB

Last pushed

6 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:8-jdk-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:8-jdk-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:10bd68f5f50f46099115c1c7f3a7769c5867df0cf669dc50e4e6c5d6fc280147
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:e9e238b866240952f7981b9c9d8903ed852cadd127be0f82f6b438659e9df3aa
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/eclipse-temurin@sha256:01ae792210f42e92f860e8d001ba6987a5c414ef986bfd05d2702a2f57b88b8a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:96b1cd9f4a4150cd1e530f5713a0aa5a2d69cd337e605724b928e40aa14740ff
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/eclipse-temurin@sha256:bcab5c799cedff0cf8680b8da75722371bde3ca526a629c7c08a7c51ac4c0e32
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:a04e12064696ce82ae3e7fb7544eca391e0bd7d9e0f3991ef7f69d9b0c16d9dc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:596ef4dd18e47629734146fa3fb897cb99c954f40b042faf54fa901243bc2248
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:0fbd5e5d2277e7a6db477a29b96b2f8e41be11d6424a9c712d950581fbd0a92f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:e12c5c8e2e4eb0767a660a0172c9c6d1c0120ad33f48bac3229ebc12e96d0947
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:c2ceeef92ac29078b807de0b0f5147f1565372ad0f72422d852b687bb3910d99
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:1d7537fdfec99002c2a427ecb952fa6d08ffd1ef95d5f256ae235b4ef2708dc0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:61c01b52376d7d6dda604b5f2ef13e61eeedd36b1b640fd06d0d97b3d2558c36
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:9df4e1a90afcfad1124aaa3ea019983e3b4ded6e69ffceaaa217660b3c43f7f8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:d7597ce178e6cd56e59c3b23d580d5faca7f4d933277efa42bc602ab447599cd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:5b7063914d28ac72916fadf14cc2a981b5f2bdcd2ce7924562c39ba5ad34bb21
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:dca3b32ea07e14f9396794904e8a020e687c19ddf9732df6693cb2e3c1f0f5ae