Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 26.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

26-debian-fips-dev, 26-debian13-fips-dev, 26-fips-dev, 26.0-debian-fips-dev, 26.0-debian13-fips-dev, 26.0-fips-dev, 26.0.2-debian-fips-dev, 26.0.2-debian13-fips-dev, 26.0.2-fips-dev, 26.0.2.11.1-debian-fips-dev, 26.0.2.11.1-debian13-fips-dev, 26.0.2.11.1-fips-dev

Index digest:

sha256:bc25ef2eb5dbed7f5c076b5a969a44ad58e8ef86dc4c9e83c43376234bc6d24e

Manifest digest:

sha256:c02c3be1b903a75bf17c165fb5dde1a7e606cf88c35d911154b83d1a447c5499

Size

238.87 MB

Last pushed

12 hours ago

Vulnerabilities

0
2
0
13
0

Support

Active until Oct 2032

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:26-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:26-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:2c684651e245ba77ba4d61f285dcb1bae5d35b957d831fd026bfb663b7223c61
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:55ffd5e416d8607bad4dc8eb988414cf8ed345ed70d4f733f39b3bce6610baf1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/amazoncorretto@sha256:ba3cbc10374a1bae6f257354aecb6e3231a1a8ffe3488698a9181b4478d3403e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:5435fafe2561d1e8c3df0f9a1aaaac09693a3232287a632836aae2eb232157eb
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/amazoncorretto@sha256:02477aae2cf7acfbaf14817161775598b0619644f12deb542cede6be0aa4909b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:d07e6ac293f1f7839730171448fdc2aa83c4cdf3f6ae8b66edece83d394e96a5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/amazoncorretto@sha256:744ac479bdda7fb8a0d104c30a41307a7f844c025642a9b716a7c0e038529f5d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:2b063b1626061fb3e7cc53a2617c95806d4369c3608404fc6f9c55ac51f7905c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:0560c6839af17d7e19136bf20a612e38b54354b6586b872ca6a70ce6ec9a3255
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:740feba0df44d58f938efdeda2f4182d6b9ad314e19ab0290e7863113f5fdd4f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:1342f88f7949e7c482bfac6ea45026786050be96d7b3223215a0413dd03b5ae6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:6bc6daa73557ab306f1df4ced725f6eb2a85ef76461224e80ae4ce8eaf580fad
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:e8c1539b520d91894f2a6ef0271c9a9f69aab83c8cccee8e02bac9c5b701c5cf
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:b42e7978010b4b3fff0f62167285eefb4833b786d86993fb6cf4d8acbbca496e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:0fe9364bcebd879c200a7d8864552cf8ce246f56b7f64ee615cc1196a47319e7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:a5ddbc5a45db793da7800ae032e9b7eab67af6a635df63ece4d29c50b85eb631
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:e464c056602a946baaebd2953dab59d27ce32fd61907930543a8aad467a9b084