Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 8.x JRE (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

8-alpine-fips, 8-alpine3.24-fips, 8.504-alpine-fips, 8.504-alpine3.24-fips, 8.504.01-alpine-fips, 8.504.01-alpine3.24-fips

Index digest:

sha256:bbd6d554bcd0512deb59b1fe5dc81fbfc665bf0b56df616be373a258407afdc1

Manifest digest:

sha256:29aeef9815893caef2b5673b6334114cba5c5326c219077c71d88a84550b8cb6

Size

48.33 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:8-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:8-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:07e999cc6bc3fde152814b5c27cafc791b86bd63d3dca602b98f485bce20a835
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:1390cc17632280785ce7f2015c3a0cfa69b35f6ad1d8d753107ffc4ee791432a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/eclipse-temurin@sha256:f9838fb41fb92a6b7e436e9490cba37e6caa32115e8a2275c8b9319b6dcb73c5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:e6a3be65968143a41474f337538942dacaed72ea97381bd38ac513e097673bd3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/eclipse-temurin@sha256:108bb7e441ac10393e08564d334bb27e36b6a649df9652c2060e95d65ddcfda8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:d80fdf2f304e37d79c1afb5344348d93b6dfef94ca372df3a3e65c64035c67cb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:04c4b6eacd3ca4f9931bb80852c0179aa0a1bd02785072ab4c73e757208e77e6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:8676d0d54aa4ae82871c3bb1658fafae1f6bb2d9178aaa18df2e62df4562af26
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:6bb88c8db6535fabb6efaa6d2277a0cbfdb4cea519cc49e1f3a4bfd7bb25f7c8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:9ed86c8a16e09c1e55b9c2376688247fe1fa31bd416ec2a7fada36e68e5aafaf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:971f9b4745b870d89cc143e28528c1479dcb45237a26ffee68240bae47cabfbe
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:0d2dba56a43a6e62784e0b406c57cabef5f81db28b13370cf1bc1acae465f088
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:4aa4e6466efde6ef1698dbc1d4826362d21f22513ad863e2c94d8f0e8bf66bfb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:62e4d5ef8c672d638825c05876ffc7ed73c946936191811d048676a6e52c1fdb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:88669a438441206f72764bfab5651511df23e0c9a5e53725c9825950474f678c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:3401aadfba5b88efd05441022c7f77baa6649209599cf5a20f55232ee01bfd55