Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 17.x (dev)

CIS
linux/amd64
debian 13
Tags:

17-debian-dev, 17-debian13-dev, 17-dev, 17.0-debian-dev, 17.0-debian13-dev, 17.0-dev, 17.0.20-debian-dev, 17.0.20-debian13-dev, 17.0.20-dev, 17.0.20.10.1-debian-dev, 17.0.20.10.1-debian13-dev, 17.0.20.10.1-dev

Index digest:

sha256:d6ccecb4530d8f00e33404a291c44334d1b436877f6f6629766fafa5c3b1c740

Manifest digest:

sha256:d75cafec2d0f6b79922596be875e8edc48e611b8c7cf12954f0230a03a29700e

Size

197.75 MB

Last pushed

4 days ago

Vulnerabilities

0
2
0
13
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:17-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:17-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:f6735f1401f7d5ea113832788c2c9ca29abd79324b355d49e4c489306194ad4c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:01a4f85430ccc220c7484bf4c2337bf28e56684f7c202963d2eed64866fe1e94
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:fa856f6c49980ef30419a4bd09c058743a0e63f1a2b2804ef89a4dd5914eaced
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:650e4b17f34f98e901afd181efb2b8647276acd50f706b1b46396b92084d02a5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/amazoncorretto@sha256:1cbab9bb6456bd11fa7bcb3e91540e4e07bcedc7f782a4c9a9d624ffd66c3508
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:fd336ce142f6eb12ca29c29631e812a9c00f1a581e46f5d30632bff44bcf3cf9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:6032119e789a442ffd1b2a0aad92697500e68e57f42e65e8d145f8fecfc6afb6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:e2f65b4148fa16ba61f63cbdb8bfdda70da26c882dcba57f52a3ee3052b67f7d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:10d4f5f4f37ec92d6a196c4b71ce4b2702b4672d9bd6d5121d7761b031dbf1fd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:343e2fb3b2b96218fe7a68903b91745e2591b3b213fa1b8fd5c11f020fdfa714
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:6ec51f24e91821b3935d76f268ce52e10e8cec473dccf9fb3287bd2a6b74d646
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:e5f563d5553e14b33bb22ad9ed4e9fb2ed9613949bdcb1074fd1e5ebb808261c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:f5deb5b5c93e230dbe563a75bbd0393a8cdd0ef93b0a6f798846db5c689363d4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:58e4f0cb672b28fbb952295f41bc9f0e62c12373e30d1a12ec86d46f90733987
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:3be2f90cc68bfdbdc3fb2da12058e1b11bb0e1db78e72c829023986a4ce4331d