Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 8.x JDK (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

8-jdk-alpine3.23-fips-dev, 8.504-jdk-alpine3.23-fips-dev, 8.504.01-jdk-alpine3.23-fips-dev

Index digest:

sha256:57489880042dd23b88556a071b2ea3373435a456c73b6d6faa9f6cdb52a2bbbc

Manifest digest:

sha256:2ed706aec305fa60559ccc9608a66ad0e578c60670d3f83826bf8162ed88b66b

Size

102.46 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:8-jdk-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:8-jdk-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:d89b364e0b940f58a105befbeab816151d6557886a952eee712c39ba7063455c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:30a3a6a9a30b7d919944a5a53f6a05f294733a1ae19d3c63016abe18fff8b22d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/eclipse-temurin@sha256:f3f7710218a3a96bbcd09f85acb05054fee5f3aec5f49784dd1ec9c2ec31b85b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:c772f1f2bc1c6df6715480360e52d6340fce9bfcfff1b1e26ad669171cbb52f6
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/eclipse-temurin@sha256:f68572f8026201d7fbf4e35c2a224a6877afb9a4645a20086b5933f10772deca
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:9cb7b1f3dadb76bb4836c2849976a12c457640edcf9a25fad10232869215815d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:25913cc87e1b3c2f59806fc496a756494252270cbecbb45fc4385c3b69fd6c42
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:30e80c5dfc48f77fa9648325ce9f5f7809e500d95c640c8dd1da4acb437007b9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:ba52acff73c1ab3c1d8655236be8a5c326a9bb70fd001ba16022fc8f15b3509d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:125936c984405633d5181711887507bbcdfe18734cecea8a65ec6752155aeca8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:0ee0a0febaccd91faa6b6d00ce047c289adf1bd784640c65d0a66496eed86574
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:b70f86e717080ca88c83e11c3a07d3ea2f7db5794d74497e3abca2ccaa9022a0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:fe99051fb644c6ef00c8bf65eb0894043042d15809f07a0acff5b526376e8ce4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:ab2ec094d41d976b2b093e4fe3ccbe7ca0787682bd109f651921f8dd1406d5a6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:7a626e8f95022f802ce11ec6250308308aa72a97cefbd5c5916ede08ec5c96b9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:657b6ba55a37ce724e8c3d42a2d5cdda449be558fccc17ad3f3edfaca1f64baf