Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 8.x JRE (dev)

CIS
linux/amd64
alpine 3.23
Tags:

8-alpine3.23-dev, 8.504-alpine3.23-dev, 8.504.01-alpine3.23-dev

Index digest:

sha256:c533ec72dc98e927c1078343bb8cbfce0fc84281253348a47dadc12e8abadc85

Manifest digest:

sha256:72137aea192d5d2bb5365ae53b0ba9b2d794808a8e76f1d1297fccd3c4b229ca

Size

38.60 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:8-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:8-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:35214c398c672380b36fca0dda91d3bbaa3b546e0a6998c934b8c142c1c66983
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:c59749bbfe56a93c6eaaad4bece71a29b83b0b06917996e23f449eeb81aead92
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:31e44d019ca0238413829dcc9fc81ad5e1dbdd5d7e86198ed757d5060893305b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:c99c1aa68161e2e222701dd969cbdbaefabb4ad414e588a94147a6796ad38151
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:ff21625f99d6f5c7917fb2537360a7cfc97c8b9a605aaf7fb778dd962f991397
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:e0bf4bed1cc045b3decd6b22dbec4313dead985fba1847feaad0572cedf42e2e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:dba78322ef4a809b99fceacb901284f06f54e860f9d02a7c9ba4741ba2e688b5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:71954314454a910a35df4a4bcb80aec9e4428435c7b9e630660862016cfbd5e6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:2315b75334a0de42cfaa4367e6c9da1fe5d223bf1fc189a204959e4c0bf997ee
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:b918beea094c7ec7d2dcaad3ae72a2c88a55d9179fefa0b63e307ae65d153468
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:71d63d898f006b5213e53f4a70c4c87971abd51dc993d360cf6e5c42f1c1e05b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:1000781cec4e288f279099f5b0305c5b4dd3e4228c96cc91990c1e91f88e2704
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:346ba28fc1862d332ca1909cd1efb0a2c0d592e508685385a87dff2c93f8ae03
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:12b9f7cdc31708875cc116721b6b4d26f184ce356ec97d366751d6e5650fdf05