Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 11.x JRE (dev)

CIS
linux/amd64
alpine 3.23
Tags:

11-alpine3.23-dev, 11.0-alpine3.23-dev, 11.0.32-alpine3.23-dev, 11.0.32.1-alpine3.23-dev

Index digest:

sha256:bfa045b759c5234004fe3d9c39216dccdb22e7d7abb65d0b2cb9128de6fcf0bf

Manifest digest:

sha256:c4907e2052c42509e5de37f7574a3f76383e8197625cdde18737b1ea66526659

Size

36.82 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:11-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:11-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:e8da56fff9ee6d2c1d7fcfd757ec5da152fd4f5c7f92a3ccd5a7df782325d9cb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:fb62105e652acc5079ca1dd0512f43d4e34ae918ec1d95092de0a559690f99e1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:9525e51d401098cf862caaf5d05e0724d245a573a2556fac45b28cb7f64b6a2c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:49f620b4d8635e5f83e09dba91d8e97aacaefb3d199edf461b9ff4ca62b01531
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:efdefd1da6d7acf120dca8332c5cab62f89ab33b0567211dad5fcf95446f961a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:24be1aa856a8c4bd94822f88cb00784b61f13fcf0a998e0ece16f67cfddef688
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:0dfb6a5a896f3a8e133697c5dc5189e577c4f46bb69d4f4e601527a9393264a7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:5a17cad49f561a32aaf8b6ac8f0c0bab99df477acfc461dfc28af269196c9e6d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:4fa09280fa9325f46dedaf02ceb1e70d98a922936065a51676913fd450aa259a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:78cb35c50370c6996b169eec287bdd876b7d23d8fffbd55c10d1382daeda64d5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:3aaf385d0fd3c9e34bfb5cbdf2fbb31578a7637ffe49850d83ed92541116d15a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:70796b7857e70d09c470954a7804d16d4b81afb9374883c52298e4dca3e055b8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:409be55a2173d8184fc0ce9c696e6863041b68558f467d7442855267c9c12f86
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:11187d7ce897f35b463e1dee5618b1085e682d134dd9642f71eb59a46ba16cb1