Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 17.x JDK (dev)

CIS
linux/amd64
alpine 3.23
Tags:

17-jdk-alpine3.23-dev, 17.0-jdk-alpine3.23-dev, 17.0.20-jdk-alpine3.23-dev, 17.0.20.8-jdk-alpine3.23-dev

Index digest:

sha256:4049492b7d40d3ab514cdd263ed5a91be9948d9238f853949570b08136b07a00

Manifest digest:

sha256:eede28af2eb6f5546622daed933349ddc285cebc64405440efba2e8e9d668f25

Size

173.28 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:17-jdk-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:17-jdk-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:c1ddbdd5b0928bfec98c507ad5a9ea9c5f7661413a1c806c442a3d493f43d8a4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:19c0ce602deef6f63f9296a86a0107f9d81a8543df39204a623e45f1e07ca5b6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:b8d52bd91d44b7b480124ec87af7c3fb42e3741fd37208a1c13dcf6ff9ec8fda
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:cb032105df14d0a27a4986b06e5f583791012de4fd5a09adc4f418a65d28f4c7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:4e74fe16b486729b5d6bf67c7b3f8f2524e0d166c075af991345c3c9f07aac1c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:86e2c552805c4176c7d00e367619170eb82269ff801c11b4f47428e1d73e640d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:632fbf9d6abd0da86fe523bc02a799ee570ae0f7344a5f2effac11cb4caa1fde
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:a3df582b6641bcdc4b3f8ffbca27d544262269d3017b4605ac6d63c0593fc8e1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:8e262f53a07dcd292393d18e539f305f9f5e62f9cc924d654de7d5cd5d194b58
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:c2e71e46edd322c5280ee9fc0a0a179c733a94a0ccaf172524563f83f17a10a8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:b597d9cec2ddb60903023766256366157a57daf38e1849271ab7421c28120087
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:13425d09b602d593ba313cfcc04fdff50b4c4157534bb95facb335eed68912c3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:b17018ef1b49e5123faf20330f54f19f1e86de1fed90befd38a13a37f84c4020
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:2670dec3f785f3b76a6b04b0d530e9c3fc1f60d4dc5e58e5250bcd7cd1fad613