Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 11.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

11-debian-fips-dev, 11-debian13-fips-dev, 11-fips-dev, 11.0-debian-fips-dev, 11.0-debian13-fips-dev, 11.0-fips-dev, 11.0.32-debian-fips-dev, 11.0.32-debian13-fips-dev, 11.0.32-fips-dev, 11.0.32.10.1-debian-fips-dev, 11.0.32.10.1-debian13-fips-dev, 11.0.32.10.1-fips-dev

Index digest:

sha256:920247b69fa4aa968819ed765a0ed3b413f2907e60dc709ea16a31869b635fab

Manifest digest:

sha256:76b58251a97279dae54ad4fe1f4a9a34f8765248a0eaf785e49169d62dce5e20

Size

208.62 MB

Last pushed

3 days ago

Vulnerabilities

1
2
0
14
1

Support

Active until Jan 2032

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:11-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:11-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:fd6450bcb15122213ab7cb872f6f375dac0a146d14b799cb826cb9b476c25dd3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:a75fcf6c4f33d18193486bfa25c1d333d1463eab71c088f686cce8a68c6650ff
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/amazoncorretto@sha256:24c5e036bdfcf0b4290817d81e9656721ee8c2f9930d732e00bfced8a7d29c06
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:1807d4d6da6d6276191844fe8eedcabd068c5ff27c86cdc8219e5fc054ad197b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/amazoncorretto@sha256:3f2fd25c7f405b97df4d3786305426e448881356ba0ffa74b13ea30675c66244
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:7fd725de8f296d043d80ac28b14e9e944bb3c344bd6903ab7106241d383cec9f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/amazoncorretto@sha256:4859a1c22ae4cfc835c82895f6bdf234f3a122afba8586a4b0cdd7450d3bd6a1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:77e4d5e8c8362989f238b0a8da0fea867bbdc21039fc17a17407bd9a42526b04
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:bc646dc658a034b23bc94edb6a537aa8e43db0a130b9ab6fe4b280ce17cb3c6d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:632fb143cc1f1c4d286072e5461047a876204b739f30fffb9c9131920bbd963d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:9878d22aee381070674042e0b95f306321bc4b29d63e681c3429e68e0a825ad9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:fd229c32fe86387386a24aaa5c9e629515af8708f2af0b14e2d70139ebfb401f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:d106a08d464e22a10bd873087b3c78980b889ce4068befe5ca74e8bbe6a0e02f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:4af9546dc377eedcb0a1c49fa273f21aea819f1ec8090d26f60f3bbe72336862
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:610d2c135cbaa0a683ef613f83025a76ea4c19dc99cb95196fdd79a0b49c2c7f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:279319be8b6681751c9b7884da3cd58d5e8c954e889b4776cbba10e90ce79b8f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:b583425a1f97b77bd1d64d89c40bd8ace9e91125620ae9883d466f3fe7dc6631