惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

T
Threat Research - Cisco Blogs
C
CERT Recently Published Vulnerability Notes
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
S
Securelist
K
Kaspersky official blog
V
Vulnerabilities – Threatpost
C
Cisco Blogs
Application and Cybersecurity Blog
Application and Cybersecurity Blog
Hacker News: Ask HN
Hacker News: Ask HN
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
S
Security Affairs
Forbes - Security
Forbes - Security
Spread Privacy
Spread Privacy
C
CXSECURITY Database RSS Feed - CXSecurity.com
P
Palo Alto Networks Blog
H
Hacker News: Front Page
L
Lohrmann on Cybersecurity
Cloudbric
Cloudbric
S
Schneier on Security
Simon Willison's Weblog
Simon Willison's Weblog
I
InfoQ
人人都是产品经理
人人都是产品经理
PCI Perspectives
PCI Perspectives
月光博客
月光博客
爱范儿
爱范儿
Jina AI
Jina AI
WordPress大学
WordPress大学
N
News and Events Feed by Topic
Cyberwarzone
Cyberwarzone
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
小众软件
小众软件
Google Online Security Blog
Google Online Security Blog
W
WeLiveSecurity
V
V2EX
阮一峰的网络日志
阮一峰的网络日志
美团技术团队
博客园 - 司徒正美
Scott Helme
Scott Helme
AI
AI
L
LangChain Blog
A
Arctic Wolf
博客园 - 【当耐特】
量子位
S
SegmentFault 最新的问题
The GitHub Blog
The GitHub Blog
MyScale Blog
MyScale Blog
腾讯CDC
博客园 - 叶小钗
Last Week in AI
Last Week in AI
S
Secure Thoughts

Adoptium Blog

Eclipse Temurin 8u492, 11.0.31, 17.0.19, 21.0.11, 25.0.3 and 26.0.1 Available Exploring Packaging Changes to Temurin JDK on AIX, Linux ppc64le and Linux s390x Eclipse Temurin 26 Available Celebrating Technical Achievements: 2025 Q4 Engineering milestones and community contributions Eclipse Temurin 8u482, 11.0.30, 17.0.18, 21.0.10 and 25.0.2 Available Adoptium's Plan to End Support for Solaris and Windows 32-bit Platforms Eclipse Temurin 8u472, 11.0.29, 17.0.17, 21.0.9 and 25.0.1 Available Eclipse Temurin 25 Available Eclipse Temurin JDK 24 enables JEP 493 Eclipse Temurin 8u462, 11.0.28, 17.0.16, 21.0.8 and 24.0.2 Available AQAvit in 2025 Eclipse Temurin 8u452, 11.0.27, 17.0.15, 21.0.7 and 24.0.1 Available Eclipse Temurin 24 Available Eclipse Temurin 8u442, 11.0.26, 17.0.14, 21.0.6 and 23.0.2 Available Eclipse Temurin 8u432, 11.0.25, 17.0.13, 21.0.5 and 23.0.1 Available Eclipse Temurin 23 Available Eclipse Temurin Reproducible Verification Builds for Secure Supply Chain Validation Eclipse Temurin 8u422, 11.0.24, 17.0.12, 21.0.4 and 22.0.2 Available Important Update: Removal of CentOS 7 Eclipse Temurin Images External audit of Temurin build and distribution processes The Scope of AQAvit Eclipse Temurin 8u412, 11.0.23, 17.0.11, 21.0.3 and 22.0.1 Available Eclipse Temurin 21 and 22 Available on RISC-V Eclipse Temurin 22 Available AQAvit Graduation Ceremony Tagged early access builds for all releases Eclipse Temurin 8u402, 11.0.22, 17.0.10 and 21.0.2 Available Eclipse Temurin 8u392, 11.0.21, 17.0.9 and 21.0.1 Available Reproducible Comparison Builds Eclipse Temurin 21 release delay Eclipse Temurin 11.0.20.1, 17.0.8.1 now available Early access builds for JDK21+ Eclipse Temurin 8u382, 11.0.20, 17.0.8 and 20.0.2 Available Peeling the Big Onion - Stripping out layers of indirection from test frameworks AdoptOpenJDK.jfrog.io has been deprecated! Adoptium Automated Deployment Of Nagios Eclipse Temurin 8u372, 11.0.19, 17.0.7 and 20.0.1 Available Adoptium Infrastructure Management With Nagios Eclipse Temurin 8u362, 11.0.18, 17.0.6 and 19.0.2 Available EMT4J – An Easier Upgrade for Java Applications Secure Software Development Framework (SSDF) at Adoptium SLSA level 2 compliance for Eclipse Temurin A month after EclipseCon - Adoptium Community day summary, and more. Adoptium Welcomes Rivos A Short Exploration of Java Class Pre-Initialization Adoptium Welcomes Google Eclipse Temurin 19 Available Availability of JDK 8u352-b05 Early Access Build A Summary of the July 2022 Retrospectives Eclipse Temurin 8u342, 11.0.16, 17.0.4 and 18.0.2 Available Verifying GPG signatures for Temurin downloads Reproducible Builds at Eclipse Adoptium Eclipse Temurin Linux (RPM/DEB) installer packages Eclipse Temurin JREs are back! Eclipse Temurin 8u312, 11.0.13, and 17.0.1 Available Creating your own runtime using jlink Eclipse Temurin 17 Available Using Jlink in Dockerfiles instead of a JRE Adoptium Celebrates First Release Adoptium to Promote Broad Range of Compatible OpenJDK Builds Eclipse Adoptium Welcomes You
SLSA build level 3 compliance on Linux and macOS for Eclipse Temurin
Stewart X Addison · 2024-01-10 · via Adoptium Blog

Introduction

Supply-chain Levels for Software Artifacts, or SLSA, is a framework with individual levels that software producers can work towards to make their software more secure, and consumers can use to make decisions based on the software package’s security posture. The Adoptium project has worked closely with the Eclipse Foundation security team to work towards making the Eclipse Temurin compliant with the SLSA specification's build requirements.

At the end of 2022 we achieved compliance with level 2 of the SLSA v0.1 specification. In April 2023 SLSA version 1.0 was released and split the specification into multiple "tracks", of which the build track is the only one currently published. If you're not familiar with the changes, check out this lightning talk from one of my colleagues. We have been able to build on our work done previously to meet build level 3 for Linux and macOS for Eclipse Temurin's build and distribution.

What have you done since declaring SLSA level 2?

We have built on top of the work covered in the earlier blog to meet the requirements of SLSA build level 3. The additional requirements were as follows:

Prevent runs from influencing one another, even within the same project

In order to achieve independence between build runs, we perform all of our Linux builds in Docker containers. These containers are instantiated, the build is run and the results saved, and then we shut down the container. This way there can be no influencing from caching or from one run impacting a subsequent one.

We have implemented a comparable system on macOS by using MacStadium's Orka which allows us to dynamically spin up virtual machines for each build run to give us a comparable level of isolation.

For other operating systems that we build on - Windows, AIX and Solaris - we are not currently set up to do something equivalent which is why we are not claiming SLSA build level 3 for those builds.

Verifying provenance artifacts

We have introduced a build verification step which can take the Software Bill of Materials (SBoM) produced as part of the build output and verify its contents as far as is practical. This will do some checks to ensure that the fields are valid and match expectations about how the product has been built. This job is stored in https://github.com/adoptium/temurin-build/blob/master/tooling as release_download_test.sh which performs SHA and GPG checks as well as running some basic checks on the downloads. It also calls validateSBOMcontent.sh to check the SBoM contents to make sure the dependencies, including compilers, listed in there match expectations. The SBoM contents now also includes the SHA256 checksums of all of the build artifacts in the components section. There is information on programatically verifying the GPG signatures in an earlier blog

In addition to all these checks we also verify after each build that the build code has the features enabled that it should have. This is done using a custom AQA test job called "smoke tests" which use the tests in the build repository in the buildAndPackage directory and test various aspects of the built JDK If these checks fail then these will be trapped early on.

We expect that all of these checks will be enhanced over time, particularly as we add more details into the SBoM.

The current SBoM can be downloaded via the adoptium API. If you are already familiar with the API for downloading JDKs, then replacing jdk with sbom in the URL will let you download the SBoM. For example, this will download the latest GA SBoM for Temurin 21 on Linux/x64:

Note that there is an enhanced version of the SBoM which includes more details on the artifacts that is already in the nightly builds and will be included for the January 2024 GA releases and beyond. We will not (and should not) regenerate the SBoM for older releases.

Prevent secret material used to sign the provenance from being accessible to user-defined build steps

The signing jobs that we use are all contained within our Jenkins CI system. These are independent of the build jobs and run as a subsequent step to avoid the credentials ever being available to the build jobs.

What's in the future?

At the moment SLSA build level 3 is the highest level available. We will look to keep up to date as updates to the specification are made available. We expect a "level 4" on the build track, and also other tracks to cover source code.

We are also continuing to work on our reproducible builds which gives an extra layer of confidence that any customers of Temurin are able to rebuild from source code in order to independently verify that nothing in our build systems have been tampered with or introduced any unexpected code. Anyone (yes, even you!) can use our fully open-source setup and build scripts to rebuild the Temurin JDK, and we encourage you to give it a try!