Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 8.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

8-alpine3.23-dev, 8.504-alpine3.23-dev, 8.504.01-alpine3.23-dev, 8.504.01.1-r0-alpine3.23-dev

Index digest:

sha256:761d6eaba202879958fefaad30e6ec0d695a59ee9ad225eb85cc7007baccb0d3

Manifest digest:

sha256:576bf3330ef5c64670857dc00670ba188e4653245f1c481547b00b85ab8fa2f0

Size

90.06 MB

Last pushed

4 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:8-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:8-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:f4de2d0079173a691a46856910a6dd895da524f6f359253ab854519131d23b31
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:e6b82f00fa77af429ed8da914cf116cdebb7db91a67b55dc1274fd38a07f3e22
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:1f301c8028d61fdf5ee7a3a837fd94ac84152f9240cb2657d36a6eec781d4b5a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:7e9113590e1221cc1ed8fecfe0a6dfafee382ad70351a475feb21fe3451ebdc0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:e247643aac0b43425ff8fa0163198bd96ea803d261cdcd3ce86c5e7b0326ecee
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:eb64016c1ca349b152274301a1bae108b6b40e2ee4fdee3da37c513feb23f19c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:7eb26665eea6a1ac9382150243b5353f7f4af51bf5006ecdd532b14bf94ab5d2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:e544a9e18d049827bf722682d19da0f72950cf35223f6022a24d8d69bd2a96f8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:664476d0307bd9143ad208bce82380c0dba3d1ccbee03edc0f885eaeeb7fc097
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:83982232e1642253538a69b7927fb10db715eb93b292a9b63c0dc0e978287526
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:061c58f0c81640614e802cd5c2f523bd17c7b670d21523bc7c9298ed64dd1910
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:9734cfe67c6422afb8de22cc244cfdd1766cc36f9eed24d7ceb646c77ac3fe9b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:5794b2f15211b3dde1d655622275a88fde5cb06f33e1c76bf1614389e46c317b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:a5848ac485fc8f81820529a266de1c0c96cfd83e62b44db9cedd67b5a9627087