Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 8.x JDK (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

8-jdk-alpine-fips-dev, 8-jdk-alpine3.24-fips-dev, 8.504-jdk-alpine-fips-dev, 8.504-jdk-alpine3.24-fips-dev, 8.504.01-jdk-alpine-fips-dev, 8.504.01-jdk-alpine3.24-fips-dev

Index digest:

sha256:2eed3844d1fc6d8a1aed5966a2c67f52e441c012e06911696bcf4bffc93beeb9

Manifest digest:

sha256:dc1e0239f88bec992c88ce8d4da97676df669c886c8f36751890bd72ca70f551

Size

101.80 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:8-jdk-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:8-jdk-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:2ab256b3e8ca682479066282c09ec0138652d8c2fb57d6153f4b0f00b53006cc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:5b26aba06b5b6b8e711dca5edf73d25b6cc1eaad652c417f0b82915236292c49
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/eclipse-temurin@sha256:fd07c60e1cf47cf8d5b581900d18c1b8cf344d25042ff9bbf055b4af9406c407
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:2b11bd60cbf080d1917d722dcaaef9fdbec90d4f30751c775fc7f240ed4e6ce7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/eclipse-temurin@sha256:eb18d556c220ca1ac3b314295fccb8c3dcf6ddc7032fed3a7ae41ac273d264bc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:97d52fa4c5348f68525fb3f2daad8796e7446a910af9899368fd0d052f17c047
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:e1826a93be2e0e5922caed8ed89f7f0839f2319d25811f13c77689c05352aa8b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:5cb5e83c1b96754e3ee0f2c69c2d18a95e90515cdb9d1aaf27478210260d70be
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:a83852533d2d8705086c4029c938c093f525d7670794c61b76762b986441853c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:519a918427d6d88f3460e8dd13308a0f334ea9787123a8df9ada31ffeea81c07
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:b19283b22b618ae29851d2203b5506277fe7f1af6ec255e1120697af97254bda
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:6c3439e46c5bd7a37b770e4af2cdbb489cf2a508f4554a800dff19b57bd2b06a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:8d731a60a444929b613e0d265154ab65847a88be33b663da7a37c43f501418b4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:15441fb3a212628357c626c4f64d245118c235b12cc76e0dfef0426686cfad50
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:0b60562b849e197f165fb44890ac0d7f23a6c89574d8a2a30a355d2c03aae284
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:3d86835f64750ea4a350b1628684b6d3b9af906c5644a9cbba4e04318ed05092