Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 11.x

CIS
linux/amd64
debian 13
Tags:

11, 11-debian, 11-debian13, 11.0, 11.0-debian, 11.0-debian13, 11.0.32, 11.0.32-debian, 11.0.32-debian13, 11.0.32.10.1, 11.0.32.10.1-debian, 11.0.32.10.1-debian13

Index digest:

sha256:9c474c81357735205c9c47107c7a078f284ab2147e6027ae6a4cab98a1975fa5

Manifest digest:

sha256:7c7d426dcddd4fcbf60cd3691ca80be78da1bea49d221547e3af9cc90f73ae34

Size

180.05 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jan 2032

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:11

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:11 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:21149cd2cf142af5fea9f4ff3089d7271cd6c6c9a3d7b1db1adb4f116a5167b3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:67354bb9ad841a5072bc0095708980d82cf4f8bcab3478d4084015a8dff0730f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:8ea90f6c5248bbe16ec444973de669cc273b7be61634cc177839e6247df46740
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:ff1c901993a10cddc9d0768d4c0134ef6897ba3daf558ab0e68593feeb7c8c97
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/amazoncorretto@sha256:0cd97f94d745f280a7f781fe0606d62fcca7089364a51ad6080cd41527ebffb7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:68d9637da34def58d485ed8e050abe0e2616e4dc88f3794733a66369f1e6a88c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:ef2ded75edd8e9c0af7cd57ae3d59afc5a1e5253eb18590f49915893675c2571
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:d373bea967ce43a21f653504117626dbbdd93bd07bf80bc005ea5cd931dfb97f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:923398da5c5d8a9e14fec4b56cb7942f9e83638f42f64956bfe642c012eaf5c9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:4d39b5d79029819f49e13f0891879b7e05fc62efed1b5357814c79976b6d7b35
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:e33d81e414a0a27bdaf3596fb8ba47da6a87b7acc5bce900c510f225d8cbd04e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:5716ab32148bc8fa4c2bd39a878b010822b133ac27afb9a3e8c7cf182bb1ed49
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:b7efbdf2f18a9a3f5e9ffef741402852ade16fa3bc49a245057e4e0028f15fd0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:2036bf82052fec307d1a817ee5acb523d6fe12e57107d4c1300901a66de4b784
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:dc0e073429b9a6ec2851db294e459d440fef7ef80a392e863c1c430aab45708e