Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 8.x JRE (dev)

CIS
linux/amd64
alpine 3.24
Tags:

8-alpine-dev, 8-alpine3.24-dev, 8.504-alpine-dev, 8.504-alpine3.24-dev, 8.504.01-alpine-dev, 8.504.01-alpine3.24-dev

Index digest:

sha256:21a5506e9322a3820a62b1872af05ddecabaff5146f024333cbcdec36d34e69d

Manifest digest:

sha256:793bb2aaeb574f14428050cfd68237bd0f659ab70d3a378d4efdb6bb36967798

Size

38.60 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:8-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:8-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:ed6244ef57cdad13f5dd28f41247d168b033a5430c98c21bffd89a3fc0a66778
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:b678cb716a56eea5f7d3defa779419ad0d459ac0f2fe4f30d66189c3102302c0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:4ae34bc1fa0848071c397c3006e8725826e5113ae4b541797d16b965384302a3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:f03152ea59bad1bd94232a340fac4d3a8b59474da0a2d5e1744bd8bf1f86978b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:ee86ce3a848da97e8c85794084739bda4e907aae905d4f17ccbb2de664ddf487
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:5cdb3ef729e65351f0aef36f203bd979bdc26e24a303727f4caa721c8919ee40
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:bbb31330ba232c1adaac78eaf5b776229fb5ce150ef7e5c022dfa63695b49535
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:e70012652cf4a9076d47df2ddae5e4d1ce1d2ec7962c1bb0f4aee2ce68a7f64d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:e2e1afd1ce778015a6a5930a80ac710946c6a4eaef6f4eac587b0344fae23067
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:7e6aa35f1832c8ddf59410c41de71fa4883fbed30dd6948e77f031829a77775a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:0a97324ffeba113554c029073a9b7def9a1ce49a30377561b5c1774460e8c12a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:36ed4be845254b043f565892aa93fd8702841da38d12530bd556d03a6be0bb27
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:4ea67fae25665e7fb521499064862ff8d725958fceafc76567373de594d4ad01
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:c482bf64f1ff6dca84fd4ad1346c12d63512fd1f240295bf9e506cfc093cc708