Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 11.x JDK (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

11-jdk-alpine3.23-fips-dev, 11.0-jdk-alpine3.23-fips-dev, 11.0.32-jdk-alpine3.23-fips-dev, 11.0.32.9-jdk-alpine3.23-fips-dev

Index digest:

sha256:af1d6f38beb758777bc9a285fc2392a46da309923ba3791d97c8ed31c94713b9

Manifest digest:

sha256:583602784ccdbd9930ca14eab0169d9a467527b93317bde4c53b118d631604e4

Size

184.82 MB

Last pushed

3 days ago

Vulnerabilities

1
3
0
0
0

Support

Active until Oct 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:11-jdk-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:11-jdk-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:6b11ebc8336e423c8fdbc4715c018669444d00e7e5c2b10748cdc354b91fdedf
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:1586539ed50d894e0aba55e8d6fb7754598a0a5a0c3419628dceb664ac5b2593
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/eclipse-temurin@sha256:e61ca3f23adf5e11484c01b53d093f0fdc9755d593896c7e6a216a63824eee24
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:4e88b3df194ae4a167f75e77af383d147ee13d46e86e7c08cb77dd94b32e10ec
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/eclipse-temurin@sha256:6acb395d4b89bffcc2b9257f929e732b6465ac33af55aecf821ed07e5ba6ebc3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:a59642bd457c1f960758e0407912d3e364a3e897620298ee127bd69a33e790ff
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:80f0aba8b661c4ffe36d8769f6aa6b9cf851cbf0e7d0b637214aa382a6cf26bf
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:29fe1859900c8795c8344188cc2e999e4a123a7b6658bdc7a2487e7e94981e6a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:40d8625b564d26e931b1bfff4eaf510ada125c82d0baf206ee5a8187d3ad41b9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:397148c040c43f4c201f4511f6aa5a5182f6fe65a88f290472971a3a0db83e31
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:398dbfb0cba92529c98e38e3350e5c85e39c5c1a42f6e1b266382dd97416a81c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:b82dabc248a0ee16808ef6115251daa288bbd05afa28554aac3d27c796d8308c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:b80dfb0f06f1240166f415406c6675df3086dd3ea578df411191d3af352ad02e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:95fd1e2ab7faded14f37e90f7df0ac7331fe496b444d08379890300b2dcbf828
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:51f5b597ef885b3256921a3c2038aec7bea1337af3f9f53adadd5c80c1451952
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:e2b959e5792620a7cbaafb1df32f76e1794b1799ddd2382aa3f4814f6a9472ef