Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 17.x JDK (dev)

CIS
linux/amd64
alpine 3.23
Tags:

17-jdk-alpine3.23-dev, 17.0-jdk-alpine3.23-dev, 17.0.20-jdk-alpine3.23-dev, 17.0.20.8-jdk-alpine3.23-dev

Index digest:

sha256:7d6e89418ab8888b5bff464b767f8902738ece7eb84befe77f0518bd90b6e846

Manifest digest:

sha256:24da527e0bc9243eabdc8220f8fd36a816f2694ca62af1b42eb128163e00f10a

Size

173.28 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:17-jdk-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:17-jdk-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:6a27426b84214b6a266f60515f8a1f671c3607f9dc346bd5fed8457c789b4f36
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:a52ba305b3080e03df2435996db807303c6e9372617b1b7bce7b02e977da0ae0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:092a75e5aaa472fd029e83720b9df58d16388d61c8acd0c70d6ac57c413f0d41
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:53354f3816171e240f59934b4dc5b03f73b15992dfda858ef9bdc3747f0a1eb4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:e201ab00357db3d76d998868529de78f725fe008c5bafbb0b43a8808190dec13
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:a47a0625b86c509d2172e5ca9884dd02bfc5c43f8fe250931a943e55f4a10e19
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:ff56d3fd2ad80afe35049d888df248ac2349f0299b7823e48a318f2cb00be62e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:6a56ad4fdabc232d387a322667e24e9a2942c467f6dc5dcab1d85db344c9dd76
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:84b1946c77a88d5a4eb0e4621f09ef79c8ad2b8ea48431e2e7de0ea85cf549d3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:f79f40c9b3a9fb24ecd92ffb6b7a1f3325fa357410cca515020954c01cc7a409
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:cdded5f2080e4c02c71428688f68164143bd5312db302063c1db4a64776a7773
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:2a3778691583e52a71a6cc273480393c601dd8ebcf7d41b24101c14b1086f6ef
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:adb407581b04fb51f841c9b1f9c0ecc0739f75d7a2a260bfa156bac54cd0322d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:6e3f963dde41f93ec5201eb6bc36137191b2f1a99179c3120cd5b161b4de025f