Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 25.x JRE (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

25-debian-fips, 25-debian13-fips, 25-fips, 25.0-debian-fips, 25.0-debian13-fips, 25.0-fips, 25.0.4.1-debian-fips, 25.0.4.1-debian13-fips, 25.0.4.1-fips

Index digest:

sha256:618fdd1e729af82a3826cd22e7bcd763bacfaca927d756003cb5800323315091

Manifest digest:

sha256:8ac783c9f9078d8f64531d5e3d4086050c7b0efee6d89cc16877a5a5d0380cc6

Size

72.26 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Sep 2031

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:25-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:25-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:0d4b569026aec9496e3c3fb0c279fca07b2eb38450fab0d49e99d54a11678978
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:a3d4849257e130671710e1b723c928d47c79177cf451a45f8a940f6a3c33e940
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/eclipse-temurin@sha256:6f8dffb40ffa1e1cef2d96997f2b6042d37af098f951b689b76157a6a87c9fa8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:6ef8e04b11f09dba8f6df0b4ead185b0f5f0b9fa8399d9dcb64f488991461c5c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/eclipse-temurin@sha256:595f156b3fec9cf93da5842eb5c6b3e85eba4a54dcb0ab6137297bf705e7cfc5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:b794eef089b76f4436ac5abbf8b688341eda3a63701bb3195b864a31bb981422
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/eclipse-temurin@sha256:948ab3dcb121b030d82be01f5b13e2c47758727358d2d6a3556c141ca2db0224
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:1bd7eb76273d65b01dfc27c0c0e6cd5a6eba2a3066c84bc2d9882a4c7e17cc46
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:48c763a7c549cd2da071e3a8b38c8aabc2ec1a5a8019357f56d2fd2fdd975b4e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:a73bdbc3ecd98c8d4d0225fae237a447df32a94aaaa648e8903a96da39bf629c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:ee5852b0079c9bb4bf88afe64b3f163d64e762c37b54b65eedd2a866b0657e5a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:54613a7aba7fac7187bcc7e557af4b5a4dccec95367777999c489aaf98f4a533
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:4b196b8b67afa724e470efd9a33ceeb3073cd6dd70d324fb270455a3719121e5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:9085486faa59061c641008dd781dad69637b433acc75fe625c4c481cd4160f28
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:fc79ad803d0f696e310c84e0a02944350a351ddbc13ce825e39b2c20eab31912
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:76a33ca05b307be6e4eb0c0cc838eecb22d58f45a715abdbba8a3ca5562d0d70
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:a134016faa1b8a768af4ab278f226467172dfbae38633b18220b861a5fdb3e9a