Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 17.x JDK (dev)

CIS
linux/amd64
debian 13
Tags:

17-jdk-debian-dev, 17-jdk-debian13-dev, 17-jdk-dev, 17.0-jdk-debian-dev, 17.0-jdk-debian13-dev, 17.0-jdk-dev, 17.0.20.1-jdk-debian-dev, 17.0.20.1-jdk-debian13-dev, 17.0.20.1-jdk-dev

Index digest:

sha256:6c7e84dbbfce5a302e51b896459f17a5d9eeca37f7b34861f17209d1ab6ee8cb

Manifest digest:

sha256:69650eebb54651ae852948476d64441146b46a38e3f615c27062889fd6987345

Size

151.84 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
2
0

Support

Active until Oct 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:17-jdk-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:17-jdk-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:d42708c6913f603f12eec67c8c4fa68c90699342c0d24fa8cf9741447b9a10fc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:e0878ac18f75ff770ccb2d9cecbc8754e269fb8ba093fda63dae2b5ebb07e1ef
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:7ab48e42edb0cd726275b40060fba9f604ba9a42ce2fdc885f2c7832c67af82e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:8f1da52241640b28d811f8a6e41f76680fe009d107c5ee0aae2dfed415f55251
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/eclipse-temurin@sha256:8605ad63bc49fd1c002cd2b29ea4abca1ac650f29aebd22369b60f849d63f94d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:901b394a5928f93b6c96d10523bad929441a2c34c2c9ace6dd4546e9ea415853
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:bc1e0b8e77846b72d6751b010e605357dd8265d5094c31cf26d3df8eb962fc78
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:b0af7d3f30714d819b25d3047bf881d8893f7d66655b79eece43814c90260310
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:23532dfdd761a37323aea14a0889691e02beb8f196bf96ee1076e8132bc30787
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:48bab26ea07539e72a86b3b526265dc5ae19435a74fc5e92b2f7b63e7d2f6bd9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:d9d333c1eb833c344b46bfa804ac16c04fbb5631bc4a6612466e262083e8fea9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:6300abdbd42125598040512617c56076457a037a4a9cd0eb900a02bb5bb8cfdb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:afffd7e1c0b10e07993fc58a788d7ebcd42dd52cd6ddd11033ac09c69c9d55c8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:ac5893109eec484e341c8a038d21300ebb3215138c9314a0cf75d204eec476bc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:d857020ee67e943a136abdd158027db880df3d9cf73b81f329463ea9ae3f2e75