Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 21.x

CIS
linux/amd64
debian 13
Tags:

21, 21-debian, 21-debian13, 21.0, 21.0-debian, 21.0-debian13, 21.0.12, 21.0.12-debian, 21.0.12-debian13, 21.0.12.9.1, 21.0.12.9.1-debian, 21.0.12.9.1-debian13

Index digest:

sha256:c479877c36f44215b877d39e4ae373763bef3eff17891f11c775e2d58b2d828b

Manifest digest:

sha256:fdd0e320a8afaf575751e70f2894799c9d4ea92262a05fe3d7e32758b5957597

Size

190.97 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:21

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:21 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:84ea862e7f52aa9372c47f1ff95e0c2568bc4d44aabcd980044c0b1fb6e80167
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:d5d0cf54beb54d664c96f5c0ca6d8f017af98af657ffd63d920943dc3a0ef62a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:9cf38fb0d08203f1d443900c9ea63f2668f58d3d4ba83ede41267b8b1b28cdce
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:5020f67ed952dfa4e988c559d8b0307b5a499dbcc35d376ecea3f428db26be2a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/amazoncorretto@sha256:36507af57993ecd06511c01dcde27cd092a617aedc56b17932b959f76e6690a9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:8469e50bd0130a7641a1e6291951d0880a242038e9d56d19e637025e3dcddf00
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:92939cd650583dc75b82eb99a71b68bc9d6ec570753665f465b07c98c42b446d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:b68872c13448c8a50a2b038a692a32a4f6a0a283b6c891aaa65a2ff164baaf71
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:54a6432065ec98dd922aa44b55ee4392b939ce77409a5d29e726941db41ce058
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:d6e21e329ddd2b2ab7cfd00309d78166d823e55aeaad1da985b5040044e5b187
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:2c9eeec6b4895e18f8bf6b86a5babe87b121bd1f69deeb833da452e7b226d3ee
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:2592feb2070d0c20487b231b170b1d64f51cc3433610ff626b8e50f712d1879b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:55d58b7651f0806aa68a65cb375edf905f4746a44b073a5f08082d1231e0f423
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:f2856605baad2c409f19375223113705ce4bd7cfdee01accd05100cb9a0bf723
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:6aea891a0da942994c1eff4a70cd8a82d3b53e2dc7253573baa6ba20898abaf0