Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 21.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

21-alpine3.23-dev, 21.0-alpine3.23-dev, 21.0.12-alpine3.23-dev, 21.0.12.9.1-r0-alpine3.23-dev

Index digest:

sha256:861937dce6c640118dc3168a7930b5ab4d926f7258487e4102fdc4f9fdcff7a4

Manifest digest:

sha256:366748aa0c110c6aac5a8d386efbbfcfdb35309aceff67a18a2b8648dcd27b06

Size

185.48 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:21-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:21-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:aa2011d8881f8cf4e0600c358ed3bfa57274e3388ab8effd1a0bed518b683358
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:6dd2ae16f8faca365064ce9b27f6331eb09c6a4b16e5f793f00056657653d427
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:782689cc05c8fa3de6083ad4b072081690c17d31e701fde944682c651866e0f8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:335a36d46b6cea425cafc6916585c2a5800b6f0514394869714d5512b25a375f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:2b98c2c0627790a3064ed4c1d74b3b6ba502fbffe220ee9d8b4158344ceae580
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:0e55281cdf7ef4b40b03b721fbdc98a830a10a8eed5b4ec9b2f447f3da36ba01
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:1b8e5fa269c2a5ffd77008f7fb0cb243bf2939465aadb126d080af618cb12a3a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:0bc7937a224d4f016f07cb49e1610d54592eccbd634c6c4b7a3fdb2cb4d571d9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:19296eb9017c781f52653347ddfd1924fb256658e6f4238a8a018dd403472c8c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:3de85372b30b72780ff4e59e28ed234cc6ec6a2aa807ee20c2dd9acfd9c7c124
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:4b8a2b88a7a7e040d964a10380e2d48e10a72b9f094963a7d0306ab5c7e227c4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:4a13403554ddeea43209bb24d100e29a9b6d336d9f68a7a3c21f77a829009cb7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:73701096d861c58a6377efa566f51ff703b6f713fd0da117c9b23fed5e58ef78
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:d8a199c046c492da95ee1c7d4a88a6e873cf502b64433e6da3efbab41445ea41