Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 8.x JDK (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

8-jdk-alpine-fips-dev, 8-jdk-alpine3.24-fips-dev, 8.504-jdk-alpine-fips-dev, 8.504-jdk-alpine3.24-fips-dev, 8.504.01-jdk-alpine-fips-dev, 8.504.01-jdk-alpine3.24-fips-dev

Index digest:

sha256:e6eb67eb3605ff492a27c60b6e4d827c0e33444abe0df034d1f9045b5e1e90e7

Manifest digest:

sha256:54b353b1356688409f1f4f2faeba20ef6fac670f1808b0db8469e12c17ba8556

Size

102.48 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:8-jdk-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:8-jdk-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:1e97ed5e2ef92422504256bfae9f42debde222200867d39cd20c7726c0bb8b60
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:02d4196aaee1795c86cd4b58cd0f7cc3bab3a830ae89e45c15472d8e945ba67e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/eclipse-temurin@sha256:f4c5a7ad766c0b9ef414fd406e01128f492707790ea44257233eff6d3f35adf9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:aad2679f4ad73f78d4478c1b6818faf6bf191e37c8efeaef6610b6de9f86a695
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/eclipse-temurin@sha256:951074af52e645cab013c3c3035cd209ac0596ce610e29c1209b009e0c918738
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:51529199825f907b079b0d060befd37571c0c16939c0c40338566ebd63a23f1c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:51ad4a67c6757edbf6ee7e2e49bf8a482d5725921c6511c47e4f5ee405b2375a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:abbae5b207f74f41aa5ad2d2812570def0dde84807cd419eefa5f5043e911f5a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:e0308dd869c565c9c92b570c61177e01922f3c057e098049c2a0fe2023c5825e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:8f684f16fa4e566912dd868ab7184cefdb80b9ab28cd8723a2b19de6bb9f2b87
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:dc04cf1c6f3a34513b746f40c36d5480dfeae1bf124e17056a07d70dba3bb69a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:1ca0f910dc5fdb7ae5b2533d83dddb99d6363b08d5bc40914da73ec1e4d6962a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:d04ea3eec7ab0245dd70658668f04f28a106cba2bed3f26a5038da13ec282a99
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:50afc284dfac135e3ade24b739835370b7d9c8dcb37abf0209cc764555221df0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:fd80576dc1af0cc6738c42ad4f475f5f51dfb60114c617329bba81f8b96c23d7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:280eff0b5760308d4dc0fdb7ee980935af59d0209501d54e43404893494cb725