Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 8.x JRE (dev)

CIS
linux/amd64
alpine 3.24
Tags:

8-alpine-dev, 8-alpine3.24-dev, 8.504-alpine-dev, 8.504-alpine3.24-dev, 8.504.01-alpine-dev, 8.504.01-alpine3.24-dev

Index digest:

sha256:755fcdd83bfadb650a8b5a814d079030c3278ba36f89060ffa61786c80280f0d

Manifest digest:

sha256:dbc75990548a5951fb175fa22e37658004d838c3c608567af3c992b2558b4d70

Size

38.60 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:8-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:8-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:14d84183293073d89a5d93f916b3387ba97d890c9f368fa6d89ee87654ff0e62
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:5cb102b44c69bbd1dda521bc8d2e921b1a542fe04e46ff295279162ccce8f518
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:bd1f7e2f8b0ca5fe1be1272867a2f228ff7191f2cbabe9cff6954c4d5eb99a80
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:ddb83d29970c25225c1efaa747661da55171f06a1e973c519ea587ba67df38ab
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:c9afc2c2171d1d30837b6a6bea42a317ee0b6194247f5311212664694ad388e5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:873ecdb5ce1e863c2d33f739563a0d89a67718cfb7fe5004854b62e54bb18acb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:8e39c05b4d199ed3472aaad00ec3225203bad29f42f25ad146b9c1d78e771be9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:8d34b7cd36276b7c3318f323c96f81806d916c50407a1c8412cafdb37951c6ce
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:98c6ce484874b833d2ab473fac4ee0a7b5d86b9525849b3d9f0b1dad44b26884
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:7f917e09cc472b4b8c1db50f1e0bfbf6db161f5563eda97d4234ce35d11274a8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:735c7f39e8322dc53bf020f6631490fe1e3afb899f9296af17c4fd31db9d403a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:2021203dd6ce422ad9318c2ba9d19f4626cb4241a79236abb3604a75535cb905
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:88dfb389dbd26a49e075af0f27ea4a53b101f5b17c6d9e0da9933c5a2586d1e7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:967d82359de3c75d6680e4d7dc4212925deffe9ed517220e8465c90ed197b3c7