Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 8.x JRE

CIS
linux/amd64
alpine 3.23
Tags:

8-alpine3.23, 8.504-alpine3.23, 8.504.01-alpine3.23

Index digest:

sha256:347f83ebb4bb4dded4ee06d487ab768cc9747e6798c3216e6b6e1791cee35c94

Manifest digest:

sha256:29ab313296573cd3628e2d1c8a2af39fd705d6423266d893ecf5abd0968a9cb2

Size

35.59 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:8-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:8-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:a31174d580ce97910abbf443a0f4d688baabc34c1a598db12c557252fae8e879
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:d0a64932f692843d4bdd4de6be478fa7f083e57dbe4d9d95386aaf3122ac6677
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:8cb1fd7f0adc898a14b2561ce64fea35651ad391521448781123123681884369
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:7febaae8c84ae8743c050ff04371336e425e4b584c75f13846c4478b4b44af65
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:794df2a06531d74a1dd9f4783b1e689fb89f8e6d8495f10310ac9e1e29dac42d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:35f4ec958b11c39f61ee9d87ff69363309ce109b86fd5c896d626c30d6a7a50e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:959e4cfbf7a87d15c2a5212057f426f7e9a8c378b17a405498b80b88d37e90cc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:1e735c12c52a81d8e500ef35614cb66dcadb8b91574827d4a0e9e5c14fda4c01
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:e35c95eda2dc7fdaed0977b8d67da8dd7265f61fb2312523f6381173de4c6259
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:89464c8b17efc1cc8de4d6e923b86eaccf3bd12e490c508c5465d836b9aeb54f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:3107d33a62af917fdda4f8668f93de97c0af044ed12878881c065f07f1545b2d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:a52e1d04dbc474c0aeaa298b28521dc610f41a8947a3dade898d32432f40fe65
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:9ba439ba2f3caea70cbf77b3b7072e8117cede105325052dbb7cb729d627d55b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:53b7cf92e026de0ffbdc517f5024361546025bac31d667654c7252da841181c3