Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 17.x JRE (dev)

CIS
linux/amd64
alpine 3.24
Tags:

17-alpine-dev, 17-alpine3.24-dev, 17.0-alpine-dev, 17.0-alpine3.24-dev, 17.0.20-alpine-dev, 17.0.20-alpine3.24-dev, 17.0.20.1-alpine-dev, 17.0.20.1-alpine3.24-dev

Index digest:

sha256:c19c1f99bd8aa0b8ad65052fc1930c112f2f41cbb3bd967f13ca621549fc5eeb

Manifest digest:

sha256:5a391b1bf2218c7268c830c30bd8336eed5917b5be6aed2bf41b2e81c8373ed6

Size

39.91 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:17-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:17-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:441e97403bad19a6fa7313cc866c30e45ece6b3db943c686c5a3c8cb5c91463b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:36b942fe93f6717c8db37c5a729c270839681c9a4331ee0e8d64486aab1c6e0e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:d3c0ff81030a807a203b76e40362605b372f13db3140bd5aec9f26607d6be474
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:e488b9ef630449fe443156f402882d217039b2b7d2b94a130ac703603377da8b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:c491430da5b43bf4706b5512e6e04578328e2da86ba05c83092dca266c6c4065
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:c0b852a24c9147e61797ef8393b6bdd1aea471902364954d603f73f6b080dc8e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:d1f5f7b7f9cf1ade966e17a235e5de715f3eeaeacdb21775737d09c29fca962b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:a096c7bcaf0e2f5fe40942e79383734ac0dd46194ed476e3719f13bf5c1859d8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:155b07b1c2c0ae3df9f0cb5dd0b0b9e7473b4e4c2343db2d21e2162c90da351c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:b8c3f8df57f208bd42743cf839a9a84a39e749f2ebd1047487b754e60d730784
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:39c3133d7f4d6d8ae724d9f5a7b0607337ede781aa3aa719cb9f033f9fe04099
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:b933c5d60ebfb60c20aefc028207c7dad91ae18eee15b9e05e6cad1491c520aa
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:48066fd4dec038586eabf8a88b84fafe98eb3cbbd62aa251c88accd2f9a70b98
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:54c886517ce5636a158aaf76d93fec174a523d163aa0e963915961b5cf77cb66