Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 11.x JRE (dev)

CIS
linux/amd64
alpine 3.24
Tags:

11-alpine-dev, 11-alpine3.24-dev, 11.0-alpine-dev, 11.0-alpine3.24-dev, 11.0.32-alpine-dev, 11.0.32-alpine3.24-dev, 11.0.32.9-alpine-dev, 11.0.32.9-alpine3.24-dev

Index digest:

sha256:03cdf72d2eb3e933a5dfa5d5319c1c30274f43534df6448c204a123302e1c803

Manifest digest:

sha256:a0c12a053d60bca54124f539eb1e0d46240fe829c590ddaa8ce84c662dd9e0ee

Size

36.85 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:11-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:11-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:1ae750a7dfd024397e7193a032ab578f85782307e713330ad3db22175c7b227a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:7007aafe0082dc7f7d8d39dfb7e48aaf47644044faa0ed1af8fc31b5d85e9363
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:4eae54daacdae4533f84f15c33b7992788c3a2429dad8d6c802ac1bc9c5d8c27
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:67674f44be4d97960df1e29341cc9ec75a98d29beb10e0004b6c63716dfef0e3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:78ccc7c282c8dc0e95a8e41caa92192422a16cd32a5864cf482507129550e50f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:508fe065066a7e495bfa884dfe1058e734a5e0f7a92ffe744a5a916ff77b9cf6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:eb6d051e0e4ccc10d65576f0a449085a8072081dc112c0db5cc4103f523d2c4a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:062909f8cd4c7b43d4409ac4bb960f0f6ea5bab47e1b6bcb14f1aa10ec6ff0dc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:33ae1e23e541962dfd5aab26722d8bf28f41bdaf45bf1de737c008aefa580c09
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:e123463aa7866753868e808fcfc3049e7ac1fe0e37e1e28a458230ac3136dfbf
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:6f78191f15ed2975d539ca2695a06289908cdbff2d3489fe70bf4ca9cc356018
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:f738fadf5e0fbe2148de518dd5dbc09ad25c0d7d399d3546383fb0c1f4512917
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:01181a9d3213d660373be0e7d52c8ad823c71d3e44c995defd8be5c7adb49b3f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:9c8cb619b2ea8b49c44cf8899e61299bf58004cae81a8f20cbdde8c2399bfdb3