Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 17.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

17-debian-fips-dev, 17-debian13-fips-dev, 17-fips-dev, 17.0-debian-fips-dev, 17.0-debian13-fips-dev, 17.0-fips-dev, 17.0.20-debian-fips-dev, 17.0.20-debian13-fips-dev, 17.0.20-fips-dev, 17.0.20.10.1-debian-fips-dev, 17.0.20.10.1-debian13-fips-dev, 17.0.20.10.1-fips-dev

Index digest:

sha256:fb7a13a0dda6b604017a476e823a054a060f8fe97ac4f934c3db71c6853d9fad

Manifest digest:

sha256:b2881c1ecca07dc0dfca5d0f5b3c3ac295e7bc72da43141d13a4b6739d3b76d8

Size

207.88 MB

Last pushed

3 days ago

Vulnerabilities

1
2
0
14
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:17-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:17-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:daa583274d39b604383f9d9b8909acf4c9bfa7b50046e76a19c635dab6c3dd17
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:edabe5076349cf4bdfecb199f7b92e5daecb625322ed43daf498db406d51c3c0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/amazoncorretto@sha256:400eb72fd0a59bc31bbdf4ed6214c4a99fc03f91f2e56f4d69d9211eebdf12b2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:241778ada735aeb81df19aacd90c3d49f24de868bf6435ce86fbb8624d1674b9
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/amazoncorretto@sha256:f81e19581c7fb1b7662b0ebafa4af7c465ed375f292ed5f9f89a5c159e7edd4b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:976364b3f4f1ba4487ea3a12cd835ed89c2c6b023af9ecdec85998791b706b37
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/amazoncorretto@sha256:900a12e4c18fd41f703f3776ddf6a29a82855123eb8954b9d289f9b9d9415844
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:ddf3e63bdd9e122d0ffe246c0aa4d32fbd82915c2a71d947b41e6493ebb23657
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:1b7012629880396fde778e18a3de31ecb57ce01b3fa985d04f2ca5e3b429b926
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:144e8dcd9e2c7382c5aca454df9d5f8f7b7d654fbecfb84e7e6b2593ce37a515
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:4a248805c59eaa6b67ea3d8e97c53c9dee55ebefb49c641db0bdc982f805efc0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:7a9eabb4d6adf59fdafbf26ae562bb0f589dccd83f532f91a93235d1ea1c19de
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:d2cb8be01426d1a95c5b7b62e2e1cce7877058e5e24b52700d8c1c2446bf67a9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:3e21cf1838004e7ee0871e9fba3a509cffe30c57fb2ecaf282be48b2b7b76996
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:a553ba7a7afca000957d0c9389c8257d31f5ac92f373e3c118b1d82cee60387f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:0f3287021beb77e3b8c8c5d47060124308185759e8cd7780b60b5e591b0bf573
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:5c349ea88384ab5a326d989b9481c42cf75dd59a92ce3037d35e3c8c26af0ab3