Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 8.x JRE (dev)

CIS
linux/amd64
alpine 3.24
Tags:

8-alpine-dev, 8-alpine3.24-dev, 8.504-alpine-dev, 8.504-alpine3.24-dev, 8.504.01-alpine-dev, 8.504.01-alpine3.24-dev

Index digest:

sha256:3b444f0bddf7803603182cb26178957ab7aad82cbb5ac0afaca03d0bf06c5c2f

Manifest digest:

sha256:67f22dd132745ecb28bfe7d540774513f3766bb7836bda3a13aa036f64f56584

Size

38.61 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:8-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:8-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:bd81e936650396c5630b7193cf90ef84351424ff8f2f9f7af32c9a499f345e21
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:48b39236f1d64779bbced2572862806d1dd4cf244870a6bac66bdac406d4adf0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:a1e8409efeab8b11e4106ce8321e1f9b7a0ec6bdc77226bd83570e3b165851d2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:de4c45077b3fad82393ba484174bb440dd5ef8fda5c3bf066c645c5437783b58
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:cf4dd7dbf0950bcb99116f201258e6b0d07a312aab32cf053d7ec2a0d5244592
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:4f81294580c4d326165c9d0a85c325bbbf694d60c694c97a49acabe94dcae857
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:f987a074f6fe71be3757438ca896c46a84bc0f7bc63854ca109344b4d5f7199a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:707bcb3a4b7268232c81f8ec56c784fba5c1a24ebc0849658b01013db6a9f74b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:3e36ae4ac18341e6e9091920c506f60280603246d8dd5a2a8280319c6a10ade7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:2a339f0c09ec15d1f37edfb465fb35dce269de5a537e6c54321f16da626f9eaf
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:e78a0584397de7137b31de4d85cbb1cb66373427200e8514e63f2159c46a935a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:4d85c5c7a7ff1a72037e3fe33f0760abf8a2e3e1225cf2500521dd3ca501b4b3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:445d36086a60f4fdc43119476b2672bc3e04576194781ffc91612357ed405583
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:8d8fcc179f34c06b62c4164ac8bf3219f25a10d3d9709f8509e00fe33e3f098f