Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 8.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

8-alpine3.23-dev, 8.504-alpine3.23-dev, 8.504.01-alpine3.23-dev, 8.504.01.1-r0-alpine3.23-dev

Index digest:

sha256:bcda13c45ac60b6be4cc679babc544ec6df2f5e65197223a2b1a263a3497964d

Manifest digest:

sha256:3d1110c5da5a0a01cbc1c826fef0cc5a6d3be4304811500eb57da72ad971d7cf

Size

90.05 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:8-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:8-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:7e05fda723f4d3b20d5c3510fe6e97718cbd4349840df54d9d8892ef69bf5adc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:d6143b77ba35ce357702efe064b9e8eb25bf76478896bb36d5fa3fa82fe6056f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:d2899a4b2d87cb86f2f2f6e06a4785b617220bcfcc36ed084e5aba867eb60795
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:c59318fcd377881fc5be98ae7107e7216d72c97863079a172e086e31eaa1dbdf
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:70d5218a92aa15acd7c9fb58245171ce7641eb51beb673ee1309523e788ce201
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:0b2cabedb33141100ea13d067b71fdc5fd964071a667064bad36b488a7d34242
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:281608edac6c70ebfa7c83675f99c1e1cc1cf2e6cc5b7a1e22b4325291446864
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:e99b003b9f602b36a3bd17cbda13879a552e0f585644708381d7c26a7588af9a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:e54a43793db27c1af3425e47b2549cd2dbe23d27d67fee85b675afd503867a40
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:eb69564560c91b7fce5800c9113288fdee08e66b57c7f1ec311bdb7b1699216c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:8abba1f7e0a22c83135de32276227b2450ba355518f0974df63493a6f989b636
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:7fffe0b405a058dd21380a3b30530356f563336d72f9ee03bd58972971d8996d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:fde635ff1df09033d95aae2271002cb980e2dc3b03ee1bf78f19a440be131f99
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:a2064277b72c398c2ebaee1865ab51b9b0c322b208d7dc6be426deecc9afd1c2