Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 8.x JRE (dev)

CIS
linux/amd64
alpine 3.23
Tags:

8-alpine3.23-dev, 8.504-alpine3.23-dev, 8.504.01-alpine3.23-dev

Index digest:

sha256:0eb118396fec0ac038bf3e134dc1fea87f268f495a6d96e7e491b26c269f86d1

Manifest digest:

sha256:4d55ec0a8cd5b1c83068e5d58ad2a420f31f422cf0bdb21f2dfa719686ce60f9

Size

38.59 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:8-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:8-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:1d2fcf0f6637e20e80618fca891209f7f707135fcecfda559a4f7b089f5be43b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:c74f0c0337cb6d51c5cfc0a04bfa472b41868813fe25e5fe21f1653ef2da3c1b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:8c5ff23ad31f5b6a7de36a0726d0603a9df8bbc8b8ed6dce0f02dc58d4d6d78d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:a2f52e92ec3b8e633fc86663d10c545cf91b8000ea9b380bd72724b3ba41add7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:a0175f0e6e166002a5b592bffd7bacdcd329cd991b1a64d86205044f66a7aca4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:76ed98f879ac109d4217a296c43f1e4d39a50125f057e69eca7593b134d3308c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:3a9703959c0d62a0ff7d83c26efbd229be7e1f0626b52f0e85c852191f079d35
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:ffb447a1ea062100fd9e6bfc3bd036d59142ad8d475310163401fbc1c3f970bc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:2c589acc032ccbeda6243dd49953362fb7988f9f5e263af021900065febd0ca0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:e12383b7a5f9942ffa16f5405d5f2f6b11ce31bd86a7bd67c3fbea8d2d57af87
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:8b6433de9f76e4bcfa65e5fef4547d63c2b7e8c9d871f8efeaae9277eb72460a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:bdc29bf8616ff486723db56c50370a883dc0b0fa60cec617a012271ace01a4a2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:3a6679611cfb77f56d09b3683d0465ee169fbdb5b740913c24cf6559e5e80941
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:c6c8c990be94cc8d746a903a6c40a1c0052b53110edc38e8dbb28c2891b1bcd5