Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 11.x JDK (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

11-jdk-alpine3.23-fips-dev, 11.0-jdk-alpine3.23-fips-dev, 11.0.32-jdk-alpine3.23-fips-dev, 11.0.32.9-jdk-alpine3.23-fips-dev

Index digest:

sha256:868ddaeef866e52c463ff9f41a9666b21eb788c9fdc4f8f70a8cc1af58a4abe5

Manifest digest:

sha256:d2a91912573c00b5f8ec0e845e0a5aa230b7cd8258913cfee70c8ac09a6eb176

Size

184.82 MB

Last pushed

3 days ago

Vulnerabilities

1
3
0
0
0

Support

Active until Oct 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:11-jdk-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:11-jdk-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:e14b400aaaee10887a63856894885285d799d3ca7e1253ec56c935871c5c9ef4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:06cdec2eda45d1ff6d46e04d2cfc877d4c14957c632c751bd120611ad412b9b7
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/eclipse-temurin@sha256:ee3bd3d931799809e91d92d83861619227dd2b46f9e46b3c7a93b0b775881a05
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:809f8541bd9d4584495ac92a205aa9268acba504048bb35c0857a8831f9344b6
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/eclipse-temurin@sha256:31135d0c7a1a72c77fbc7ced3b7d3970f47cf00f07ea877fc906efb01fa4a46c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:2d88df519435f73380dd0e2d98a81afff128bfe3553663613bf5cac6992e75c7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:474c1fdd0c70ed9e07c04be8b897ab2c1b09e407b7b869e3b52df697eb81034b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:26345951a14696139301341c6a2b864250e9c1f55656a6fedc053747fbc538d7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:2ee939daf0b9bc82de7e0154d03e03b89202c1b63c1c36adf616ab5eacb6ec36
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:1ee231c6d70658402119d9c25640e8de83421677c70b981e176bd786a592ed69
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:f6be0dce1a1600700b5475f8ec704d5457547b3fd25666f8478d2e9bdaadc026
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:d912e44426775524a52e9dd766005e34b6ff6eb9b00c1e6dc5689210a018f578
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:c31087cbb8892e88ea6718ee2c41ff1642538f63472a163365c57274b54d0f90
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:abb3919beaf38dc04d800806b463590ce10088632ee70eb53ad8cf16fbeba9ce
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:fa2633503dee610e68995dc0b57ba4e079856f7c09fa37d5f4da815b65763ba0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:155b0e29a06a3ee75ae5ac554c74b3c725d1d4efacdb20b027006d2c1728c2c9