Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 17.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

17-alpine-dev, 17-alpine3.24-dev, 17.0-alpine-dev, 17.0-alpine3.24-dev, 17.0.20-alpine-dev, 17.0.20-alpine3.24-dev, 17.0.20.10.1-r0-alpine-dev, 17.0.20.10.1-r0-alpine3.24-dev

Index digest:

sha256:2177e126dc629bb3d60e4951d1108a57b8a53d360470a3eae4eac38dff472fb9

Manifest digest:

sha256:9c71ca531a33ef2c89b01dd3e7283a1a463bee9cad3eb31ee459a6efb5fedbf1

Size

173.73 MB

Last pushed

18 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:17-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:17-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:ef271f3db9921dda141edb7b446cd60b869bb0e2741001dc860f6fd0dcfb2697
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:1ab2e43d63f4922d9666fd8bfb95c451bd910dc523cd5480e6026ef454980222
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:78b902dc8136233d68cf879ad4c9a279c8c024267f41d3836876ed2ecb5abf00
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:afe3b0e00070260f23a8300db99e1be6f2820e22acae742ab07ac535a17d66b2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:701f09165f4ecbf5357239beb6c2fc2257a1653b037d90b2f9aa4b40e9a4900e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:8335e8e25e6c56b55337dbdf67ddea82bf027ee1f295d9dc4c3577f3a889da31
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:3d7b7ccba2ac0595d34ecf126a59dc906d0654a25fd10a2bff583777cda3c77d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:ae9c6932422b89f8364788a1be2680be7794f5edd5049a138c1ffdc54bd37b56
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:1e18317d563b2ddff63c9f7e625486f5475185fdb42aecd877940db9d16a28ee
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:65bdc884737a623d0c6d4e671f8d60dedd9e6c37ecb68986252b779da002c870
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:c86f9efcdc9e50620bf5e45f3f697614404480c9ceebbde945341c05331e4363
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:b602c4b138376483bda07c216696b7edf216f6bb5a72a9f30292856639ad9ab6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:a374a9dbb5f45e248d2934e17d65a147b292c141bd38ae0a13367c376338ff75
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:800317467ba78385451d5bfc9ee11d68d312a8fd4eb03f2bfa78a467b3408698