Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 17.x JRE (dev)

CIS
linux/amd64
alpine 3.24
Tags:

17-alpine-dev, 17-alpine3.24-dev, 17.0-alpine-dev, 17.0-alpine3.24-dev, 17.0.20-alpine-dev, 17.0.20-alpine3.24-dev, 17.0.20.1-alpine-dev, 17.0.20.1-alpine3.24-dev

Index digest:

sha256:077e2013d0a4255e1705fb10f7b650fb426486ab2e4f411a0c4d5ab01e34e2e5

Manifest digest:

sha256:1da73f0de87d2ce934f8fd33b7aeaa4700ee322c0c147089704a63662fcba619

Size

39.91 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:17-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:17-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:a03000dbbbb9a0456f64a74d6abe7fce997447c43fa10c07f0193e6edaf7efc2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:9e54581f50cc37d2704535d4ed0c040871363bf214479db5d36e8af0fca0cf4f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:9e056bdc0cda9645453e85c31bb73e4a9b8356d238ddd042b95bd152fcb1d200
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:2f3fb003c38c6aa0c31dcb5542ac386350f540b2a8e4e41863791607def1003d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:73f93db299ba81bcddf3ba83f80923d953d77fb0b978efc5ee7af63ba1acd1a2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:18520fbf9d0285c18f485986cf29ed3aca4a3e82d8f195220486eb86ded6726b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:f627ab5944908beb15e5e28f44237970dc60d8c5bd158a19e9c4eab14bc1aff9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:6fc212fd6648979c81ee5dd82b326859c555770fc772d3a34e27e12d3d62bbfb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:69d71d3aa9e93edde3e6a31d5dc8cc1664ee7d7f714e74a55c3b12c6d68e35f8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:819c6775ca49d9d23f74a39224eb6fae2b1ba6c817b23f5fb6c423e93e3a7f72
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:d227a8359dde63a6ae2eb9b0a0e746aea3a94a45d2fbee769fef6dbbe918392a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:5c0975c99e15133e57491adee5c8b56fcb898bd7581fa6da5c6a6b14ef828ad1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:6da020106ce13f6b9e597b1ad86ada091cb1806cd6d908dc49b57c348ffc518d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:eb3f0f6169f79fbe95d707db8a3404ab0716910dced333643d999903570a45d0