Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 8.x JRE

CIS
linux/amd64
alpine 3.24
Tags:

8-alpine, 8-alpine3.24, 8.504-alpine, 8.504-alpine3.24, 8.504.01-alpine, 8.504.01-alpine3.24

Index digest:

sha256:8e58ff57249697e631b5ca65def45afcbc787443c6a3f4cddbb2fa941e978e77

Manifest digest:

sha256:58fd470e7fca2e65ce869da7a3e2f7e619215f01e100e30537815c8f085bbe07

Size

35.60 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:8-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:8-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:a762e69884c3e11924ad74b6508933834773e75c907556f5d882d45ba19e8645
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:aae12e4838f116d87f2ae136cde744b1c8787e14ac454d58e40dbdf3ae5bb031
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:77b2ece54feda5092dacce3f1d13676dc49e2cc0ddf4f6c9b81dd860a41e0c94
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:c687ffedd6e86d147aad6e5d0df7e520020a66ef8d8b9aedd8cd546db4812365
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:1a0a7dd168ab5255991f8ba1f8693166720a28791d26fb3cd8828275ccf0ed55
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:3a408b32983cd06b951ea180b47fe930cd73684f6671b06631cd6c4ec69ade36
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:c72c0acc6efc88a064bd6e8be0fe89c3d5ade3a202beddb7b449360dbec779fb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:133094914f5063e1a4d99ad9bcc5382c96c0cb7d10072962a66ffb28a93bf8ba
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:948f83626021b0f501b02d12486cf792841f86b8aeb8bdc70ecccdd18e38733f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:7ba670a6330c858bf20790d6a76ee62b186a8db713af5cd19a19d5d075ab1677
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:cb56fd7cc2b7c5b580c653b61e6a13c9f034c96a7bfb383214ff8974e137a53e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:e03fabce5b1208be5f4ce788acfaaeac263c14e2af04ee445c5728ca07699f23
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:c34b686faa583de164430d850f8b1804ee8e91721eabcbe205489c2cb37dec3a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:7ae49f4d55556dea26f92e7cc20dc37f3ce414dd3416fb74e606856b9562d159