Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 25.x (dev)

CIS
linux/amd64
debian 13
Tags:

25-debian-dev, 25-debian13-dev, 25-dev, 25.0-debian-dev, 25.0-debian13-dev, 25.0-dev, 25.0.4-debian-dev, 25.0.4-debian13-dev, 25.0.4-dev, 25.0.4.8.1-debian-dev, 25.0.4.8.1-debian13-dev, 25.0.4.8.1-dev

Index digest:

sha256:c7a820099e4a9370730fa1e94232106ccfec5826d1b3c75a8857ee711b808a98

Manifest digest:

sha256:51b2cfea36a292b26a48119fde5ec6e99bd01bc9b488428c65d81e49d5687953

Size

227.56 MB

Last pushed

3 days ago

Vulnerabilities

0
1
0
13
0

Support

Active until Oct 2032

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:25-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:25-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:d9d075abcc82cfa6b72f1c91c95d7a300877d74286d51f5ed2f0abad0eede8ef
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:2826e378b58c790b26ebab092c7eaf9d2da93d35a874b1634e570efa79b32733
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:00d3e4f5604ed4f498434469da2b933adf77d419805699094c7b20bd674e8bec
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:41c156c65c11e6cc472a0bcab058d965340ea8ff1d6086dd3286842eeae8369b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/amazoncorretto@sha256:36c5bb8074dc7da78502b832d190b7b346d54ec2bc61367adc15515f6e5a2ad6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:6e6541683f4de1df19c89f1c10ac2c07b2464faee1ebe0aa1d1fcf2259d7b1d9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:5680ab3c832023a7e12448a668c8c30f22e0ca71c6c664476fd61b43347e1d9e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:ec0c8c07af0d599bcecea450021a73503cd843f1f7976f9f1b45fc399413bd51
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:0ed4a06abc378070dc8e87d00d3fe7994873344a3f93ef3b5273d2a9c2f2e387
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:ec294f74a0bfcf23080bd34e5715b0f805d8ef0bc6001865f03c146af9ae7a51
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:858b8b207511cd56027b35f14d6ed246f65e7fcd319181e8d91f95c5f88766ca
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:bd0ed57990084fe47f054965acc1d44bdef8c2362b8404bfbee135b04bc9c568
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:c71e703d5fa122a9164d9717906f9c3579bd6385bd1f88a3a78f36a4b017b222
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:d739e1ea6095b22691d90adabbdc1960e97d1d88a2c7c9776fb48a50df0ca75b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:d9215c2b94f5a4dcb4ae36fe82601629a3f027bf794fa6233a1eca09f606ec13