Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 8.x

CIS
linux/amd64
alpine 3.23
Tags:

8-alpine3.23, 8.504-alpine3.23, 8.504.01-alpine3.23, 8.504.01.1-r0-alpine3.23

Index digest:

sha256:4914a8c04d578738ec3aa8e65ddab1781938ecb0e9ad2b109186d1ca5180ea5c

Manifest digest:

sha256:562f23d10fa19295905fbf747102b59e66e188d1a42c9ee3f5cbf0b55e5a8d30

Size

87.11 MB

Last pushed

6 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:8-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:8-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:226dc397203a5907ac92d5c0b219c3b99fc14c5c8e135ea1681f551c265616a5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:99bcd3a46c4c55feaa6b9d4b896a07d272c1565eff5dc59c6e22eb23b21237da
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:738ea24c8f5182bed7eff91eda887dd6c3827173f340f17e4ebaceb7f7caa5ca
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:881f7048f86407a5a5ebd472ed292b8b52572dd1c97748977537245780617d6b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:1d1666029e72648cd23dcb2d3dd7deae5e353427d8de49e0d92332c3b4f21bfa
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:bb13dfea0a2aae87d6638df790dec7e4a7abeff3fe2894b982a30eb7b256819f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:8fcfb5dc49fb6f5ac38ffca12de9b8e50ed0621641854028cc69ad680d2debeb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:2a0162c00540e2d614553eee7be60ba0122b31e2b3b0a7aade7872337a263d5b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:124ede8d26a76058ab4ea2b79513f2f399b63eaa14fca294206e5f4ee9884d5c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:97db8a59a94a77f4fe3eb01bb23464c3963f80c367cdf301ffca383c2131563f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:b6aa671e21106459f53b605f2dbfa32dd01e0823ea607a7bcd075d87e55e5268
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:bad50b6a8cb4571c7bacc70acb07891d80566fb3180a185c23572ca30748edde
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:62795a6110433d6fb1309ab4fea832e489b892fafcbe7ef913b2dd86c16dcdcf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:e0813e45fbbedef7a9fca727c4d8d1c77f293cef73e6fc2092ae629dc38f4055