Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 11.x JDK (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

11-jdk-alpine-fips-dev, 11-jdk-alpine3.24-fips-dev, 11.0-jdk-alpine-fips-dev, 11.0-jdk-alpine3.24-fips-dev, 11.0.32-jdk-alpine-fips-dev, 11.0.32-jdk-alpine3.24-fips-dev, 11.0.32.9-jdk-alpine-fips-dev, 11.0.32.9-jdk-alpine3.24-fips-dev

Index digest:

sha256:f9ad0b291c55fc2451f478fa245033587932362541c464c0803e30fe8ec79f23

Manifest digest:

sha256:c1101b32b0af80383c85e2b108e08f5228af06aca42ec1bb7fead07da309fc96

Size

184.84 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:11-jdk-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:11-jdk-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:1334ffb9c8888500d11388af0ad814553f86d6084a4f0bfb76fb200fb838e9fc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:4884570a34b61c1a176f7b33b6486b565c777a21fd0f19f40565eefc58297085
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/eclipse-temurin@sha256:a359e71fd177047611e84f4aaf077fda9febfd816506b01183701ccd0051985c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:2a82464b6d84964a3e91fd86e74a9d6e986a2fbf080d63f7c4e5770a67210e5c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/eclipse-temurin@sha256:71d7a9d6ca23f5456fc19e264ea28e5505f67bfcee56feaf2b6f5c88d0b8a67d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:2c2003b6ffa68e144811bdc4c7a16664402cff4f97adb02115eeec91c605ed54
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:654ef2895823737b71e9b0eee2b4d400e812d99cb3e30ee78056b7f0bc15b0a8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:eada77e7bb99410bb64792bb4d0a2b1109bd1bbf01d04cbbab592f2695df558a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:523a861f67c2c7d38cc0b98e8844b80431fce7f2b605e73e160292b23d337f0f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:e0d5a237459e09550751a4e5566d525140cd2cb3b2253fb8bfdfb3bf6bfc83d6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:a190bf4428a90a1643e57d6798a39c3d535da72a275283cc9205cda8ad69b93f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:f0875f1494db04bfe8b13f6a7d1f3cbab01d75620a9311ca1a32623647547e05
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:0b0512af5a224ee2bf3314da957c4ea936580419ee23d8aa7bd701ce34d87182
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:edf6766216108ac6be58348585bf50fdb1226fb7063e7c4bd03e1a9a1bcd7dab
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:95c28e0b0ced32f73f243097760ccaf0652a71e50f15e1703aa1687fbcdbf35b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:9f2d44bdc9404f2a5cf815ade797c62c91edbb7e03da02092292b5eceb306b61