Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 8.x JRE

CIS
linux/amd64
alpine 3.24
Tags:

8-alpine, 8-alpine3.24, 8.504-alpine, 8.504-alpine3.24, 8.504.01-alpine, 8.504.01-alpine3.24

Index digest:

sha256:1919c7ea3b5d77a35866042be8dd54b4e33287207d31e720f29f52c61ca315ed

Manifest digest:

sha256:96bbd846058c64d69fc99a27210be9054b0afce09d54561848c4cb30854274ec

Size

35.60 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:8-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:8-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:10e18eb259a90b2394505b5683e536e0cef44732c4df7c7ffa72e8e2bdfadbe7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:c0de50330b7c79b2a301c729843a4b5eb5bc5b29837e3b33fcca603402488cea
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:a8aea70bf12e12cdab636195602278a2dea20dea10e335f44be76689310b7dda
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:2b7c64da223c1d09a01dde2842a3a3b648ce24d5acb304f1d77ca06e0e1c60b3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:aa01f979cca0d9aa9d61c0e647fe7354f426475a7c8b527fbc75cbff75d11cb3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:8a142d9eff9e6454d92928cb53ce4351c6b25cc6a01a9fcc28fd7e29cc92f6de
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:fd3b1692d3ac75cd6daaa428262b9146b9f1efe9cc3d4e6d83aa11f0f00e1cbf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:444425a7d7596f7d89f5797124ff4e68ca15ab2a55a95a89ea15d9f8672d4559
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:d97031d267981e75e838a8ef1768c19ff7e4b709096beba6aa9b1e7d670025e9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:58ab66bcc9b3cd31f445e85be756b5edc29d818dadacda16cb5efc7e168b123b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:e386cd8c63819a109fc4aed4f6a3b59f6b372672916ac2c4337e4d6f03a50971
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:ba8c193f982fcf0161390d7fd39e80c4d57d60de3073017cd30bf35ff4ddd435
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:6b917084297e3ab419d83287d574689be45ea54a0967fa8cac2781099c9a92e4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:b62089da64cd7d1490b6924501851ea7e92e41afd6d28157cfdfa2db9b53ab2f