Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 8.x JRE (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

8-alpine3.23-fips, 8.504-alpine3.23-fips, 8.504.01-alpine3.23-fips

Index digest:

sha256:63a29de01a507a7054affd6038dff073f86b3b3d930c68a8021b1a38db0e5e60

Manifest digest:

sha256:3d062b5a1b760e29ea13e7089e22a3574697680bdcdceba0b21ac9d4af0171a8

Size

48.30 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:8-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:8-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:0d60a4048cc4ea6cf4474140ff3d423618ccf9c2307d313b29fc53c636dea47e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:b17ac495f13c98ea4db446bacac4993e4c18b0486f6a89ecec91dc2b9b26f1bb
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/eclipse-temurin@sha256:78d0b978ccf3fdc0828afefd42a5d00295eeed0cfcea1761cd01c0c778dc4bf4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:f5ce1fb213ce01c57c496d42ff572f94371cc19118e933ef50e8e73e0d2e4755
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/eclipse-temurin@sha256:8862e38ef87b7cbccb220c1e6998ba52242adff606d695e6724bfceee605d5c2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:67924ccb33a056c517827e92598a5005147bc023e053d37c54e62cabbc25e8c8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:3f3b35b0ff6f6459ec14eaad5622d16258fdbcc7f2a968f4803111ed038e82f9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:13bbf675cebb602c440e9dece50f2e1b13b7175653fe2d5f1a9fe3752309eb1d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:65ada8dc1af76cec2eb9d285a70cbf0a2ac87163914260f2bb9ced441451dc10
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:9dc07bad7d0599417a9869727631e89ac8b9530add52e9306e3fff9d5a00ccb2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:4458711d91d546a134b0e58bcbbc910804bdc61b6aa6cee4d8d368503b085ee5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:8e0e431f3472fce50674b111e72c9a44ffcd477761ed070dafb67c097f435a98
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:f32e9de822ebea4e8c1610a3cefb152ba1d223ad41538b46c1633b9a62779d84
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:3e2709ac18ae64683e1bf391d0f29f3b51b23d194138879a3905cdc5050f637a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:afdbbd8fada54a24cef2cae200a9027a2f595a00586ecb307061921a6de6f4fc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:f91c55df8273f58274626db197cd51a565cf334d2f041b9d7c310412b0405752