Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 8.x JRE (dev)

CIS
linux/amd64
alpine 3.24
Tags:

8-alpine-dev, 8-alpine3.24-dev, 8.504-alpine-dev, 8.504-alpine3.24-dev, 8.504.01-alpine-dev, 8.504.01-alpine3.24-dev

Index digest:

sha256:1848092cdae1fd71c5cfe9ad2147418f8ad16bdaecd675e7f5595f41327faf88

Manifest digest:

sha256:29a070f02da51fa00e89a1b4ee145b1d1bb5d13ff020af79f1208554bbb4aa02

Size

38.60 MB

Last pushed

6 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:8-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:8-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:cd1dfe884f86554db96a58cea31c238916ac2dbbb738a486ed244c8689b50e97
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:d5d8e529386552e2e5fd275e597e8b8ccc48c8fd185d2c4a2504c1510ac7efab
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:4605a4c4d6818a26221a9878016c1aaefdc4eb2d11d30c8f5a9a85a8b39a45c7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:21690b7989266b252244f3288d0db41e9e3a15b3b6a43ead7e564a50b7913959
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:6b062901f54583ae5c62b837ce6d213587de8615d686960ec6432fedc09b2fb0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:476d60c93c09934f3c20983e5a3e0049e45f33717352e96d60b335312911926e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:ee524e3818344607c3465820e5c7c19327a884cc5447b4697631a090d00ee378
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:b7b0dd88adaabe45b07754b790e6ff81e4829672b4b470988e29e2726042ef80
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:4ae5dca2cfc64c6d40a41dcb25d73a41511ef6a6b6d9ed1f7d603a709560d388
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:623296812f56c630425830c5517913e18116285fdba8954c7c0045c198e49bab
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:f55f56efb0558fcce9886d655448eeecb81392dfffa5f077bf26792a6b0257f7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:6dd00abd01367c520ce9d8612807b6db8bc919a168f8e33001af91dd7cd8e7ef
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:1d793df558ce08c53aa494973cdf181ce1815e09fa5bf0c3df54d4f1417f0550
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:5968880b9b484d542b330ab42c874154c2aef76ebabcc62ffb1eaaee1a32f0e2