Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 21.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

21-alpine-dev, 21-alpine3.24-dev, 21.0-alpine-dev, 21.0-alpine3.24-dev, 21.0.12-alpine-dev, 21.0.12-alpine3.24-dev, 21.0.12.9.1-r0-alpine-dev, 21.0.12.9.1-r0-alpine3.24-dev

Index digest:

sha256:33e7cb7b665fe49ee02a59d6dc878f3d6a432ff83c6b796641a6aa0774681dbe

Manifest digest:

sha256:003b38545677a3362a2d210acc9616260f49d5a8d1f0b442ceae111b411ecf50

Size

185.53 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:21-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:21-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:13918351f75e961de56f6f433b8c08ebd2f26457e546d384b23447be9e0bcd32
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:9ebfdbc05d424dbf7f5f3840e633951b2d05c47cda9aed99b697c3b6297ab968
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:71af89094891e71039e2e7dd4d60b7291755a47465e66f75d37a3acc43e67df0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:81ad236008342627932f7de2e5ae6f71e2626b27437d096cf99f3167e9786248
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:56fbc19d2cce348da80745bac3c2b8443660e50294ea4fb0d146e0869dafd77e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:35fcd36b988d524ac423c3901d136512395d8b79307e9035eb2c1031f61971e4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:2c4a39ef70e572ddcd39d61e1b0e91ecfbb4cfe2518498cebc6fd8217bfb7d7b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:686138837442c2572c4745ccee377af13cde574d6e5cf4a526747a8dc0e4dcf7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:9f1e2e099ea739f3d96c2596343f4608c4df7dd9a873be5d633a03f41bdf7c24
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:93ae4ad7d7b4260ddf82734e8a61ab2cc7aa4f09b8ab8cfef7ead8592a8eae26
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:464d60bd6b82c81348aaf5a2f6fb270712d0156edb809346fff7133c4551d1d3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:c614dc8005b7178bd4dd69b3b3ec40aadee6b2848c5b9992e6630908a23c173d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:123eaba5fa904bf3f19dcb01ec1f7fd226576dce78ddea71b693398f78f50291
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:e40090a54759c6356bab38b8efced9945bd7b47ed8b61d087bd519698a377d4b