Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 17.x JRE (dev)

CIS
linux/amd64
alpine 3.24
Tags:

17-alpine-dev, 17-alpine3.24-dev, 17.0-alpine-dev, 17.0-alpine3.24-dev, 17.0.20-alpine-dev, 17.0.20-alpine3.24-dev, 17.0.20.1-alpine-dev, 17.0.20.1-alpine3.24-dev

Index digest:

sha256:0db34e9c6fc2bbaa249809ca53c46492dd4faae08c9692d101d3a8e33707a580

Manifest digest:

sha256:2a36d11f88aeb1a1c287d51851607aa67ceb5fbee6c01909a1dd534c79f6e8de

Size

39.91 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:17-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:17-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:2fc99b1da3d387fcd9fc372404b75b271547362a7dfba03a1c7de79b8c79c40d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:6b04d06f44c49e1767ea8cca4a56e8f874edcb18f669e8a08d1ffcf758b6de94
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:e53788867d57fce5fef16f5c038c96c670f6347103f2789254d3b0a3d5fb5290
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:cf3ba41a1ae06a9d08ccc6e06e79af5db1d70b802ab11c1fcc2647dce92845d8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:1205aecf637510deb7615a9c78c2134df0709ff1c8cdf817e25f3902140c7e81
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:cfb4c7e719ef89583c910a0d22e5da56549886e231224498e2176d48b9a16660
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:adf751f04a6a3d28a9b7bbeab920df8163339ddabb9b4bbfd14984ab38b78cde
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:34deb5270f9dbf90b7e697c35d7830d9b7746fcd81f61fc0e80b5b3ff0e1cd83
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:da8a86232adf2107555b1aa87075eb12d9a62620d967c61fa1bf99d0f41a36cb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:5a5c33592238a2e827ea41d92713f812d2334a5b4e897166f717b8f957aa4273
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:c480c36e2422e500812b4c64ba5ac34e742676e2e4b9501b902e33e00bcfeb77
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:82c7a8b1ad683f234300e29e0da683807ad8e4d10860a8072104466ac34e09ac
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:5e262ad0dea80fd1470a54f45ef50870926134c193a96557487d173b152ed8be
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:19e62dcce17bbe9b39bcffb22b9978c5507be49c3718a92e749fa7f8889c038e