Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 8.x JRE (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips, 8-debian13-fips, 8-fips, 8u504-debian-fips, 8u504-debian13-fips, 8u504-fips, 8u504.b01-debian-fips, 8u504.b01-debian13-fips, 8u504.b01-fips

Index digest:

sha256:f39033a978cbacf140134618b02979d5f1f45223a6c52f995ffc80bc0d750657

Manifest digest:

sha256:0d2060f872a435d08343bbb7a654dcdc02dbf42d8daa16dd998f0d03e1093cac

Size

57.85 MB

Last pushed

5 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:8-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:8-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:872be3bece235f67abccd3c2996563ac01ecf861f72ea3f1ea5862f0c13f3f35
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:0a5252e725f5575c5e3fb0697538517f68b0e385349bd864ec2e5be0ccd8142a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/eclipse-temurin@sha256:476f68fa645cdbb41885347d1026241d30da861bab688a6198f42762d827f339
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:23af65ba762a1c38c28be21f30957e6079be0478da85ecbaf2b8183a2c08d6ce
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/eclipse-temurin@sha256:4fe06ee115d5c4b592b48ecb897b1fa66adf13332dcc7c19a3d01045a39b166e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:83340a09a5ef3e3601926712448488b3a7c020115374aa3659700eb75123666c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/eclipse-temurin@sha256:642abfcee68f7da16d820e39d4f0cc4fd94ad8c30e7ac54df01b61d2c939fdd5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:7b59019b737f942109b8bfacf1d0fb31517dad05e8811177c4318e7960eb6d28
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:fed14d7b1a674db9dafbf7995dca8144eb7d714d3e918a6558e6e0336f5833c3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:3b304b075dd42a3b36ee676bcd3685182d496e29ce4fe0134b6e4091ca4d1242
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:6c012ea284cb07cc4d9f91ea0cffc6bdf4871dcf3deeb91bd3c41df0d80ed774
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:1e5ac257bf48f290f970abcb0107c4f828d0b3e9e9941024ef8f85474608482a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:e44fdeb421cafb5514ea9fb10d142c4bc1713cc13b5fb1f47b07a6cf9b29bd69
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:7976f89ddeb70d9e6979ebef42d867e3b2cf8e8f1bafc4e58e2d76ed4cf24585
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:90cfc18184554093e6b3db9225ecf98fe7cb4411926c1e134254614b16f8ae50
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:a7a2e9e6e3269d0cfcd1f388d7839d0cdd42d0da348d2903cc89a58a11f19730
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:dc5e0929906583db7c94f7c88d2a384e0a62ed0bf833806b89f5449c04137042