Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 17.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

17-alpine3.23-dev, 17.0-alpine3.23-dev, 17.0.20-alpine3.23-dev, 17.0.20.10.1-r0-alpine3.23-dev

Index digest:

sha256:6230e6b79b9d8313e93b72d2f097ebe8ddcf99c24e27e76beb3c988e7029eea2

Manifest digest:

sha256:4b2b785b0b7bacfd47621409fe6a83e6626979924631334d5cc784712ef98521

Size

173.74 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:17-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:17-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:fffb9f523f4fe863edf12ff3e8cb8ad9d97cecaeac5f0f71dce398404164ac91
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:ddb54dcce7fec7fc96eb2b7443eb3db8401ae45d362421ae383714197ed69ca4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:46f4f3f1c678f7d19b50848fb20c0de26a172eddc7b74748033c062d31f8b1a4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:e70471c8bdde69e9b94de3c2485127a6d9129fbadcd25044162be4192b8e8c85
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:27f98b78471f807c494f578bb28e271b0b730687e21c4d91255b4aa19a70678a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:354c74caaf8273df071f4f1f92de99180b9ce5df50df6ea068fdb83b95f915ef
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:2f4a4e3697aac37dfc1ef0d9dc5b1fb6e4d2d7a75b202d80d9be63aa60d0d531
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:19a9a374dce4885593d1c714c9ea24ca624915db1cb8e3036d4b2555ebf974f8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:fd0aa41a73804c58c236bddc0b9a67bfcaed1f0553c97befd14dd95b33007fd1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:4abc3aa3b67c274d867275f382e09d771d0d16f13fbe1cb9875715e19a7e3890
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:f186199217d7e065b51e2eb7fb8d6f6f2e2566bb3a393e6e1bdf9eb72c5988a3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:39a54af4cabb3f7147ed8c42e045b260aed02d3a413d40a82f65df61c4c50d14
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:f51dd7d6783563ebfd31c211e08a0a378ee0bf81915597cd0290d5255505b175
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:4f7ce143af557ef66996a07600c0d02df8d0c195692a6478c4aa15edd3164c19