Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 8.x (dev)

CIS
linux/amd64
debian 13
Tags:

8-debian-dev, 8-debian13-dev, 8-dev, 8.504-debian-dev, 8.504-debian13-dev, 8.504-dev, 8.504.01-debian-dev, 8.504.01-debian13-dev, 8.504.01-dev, 8.504.01.1-debian-dev, 8.504.01.1-debian13-dev, 8.504.01.1-dev

Index digest:

sha256:f00f8a0d72d5279fc7530f1375e3c6e5a452ac96800b6878ddef987fce3bfd55

Manifest digest:

sha256:685aaec45fd388ab54849feba680606cbc1af9149ff01844b7f0cfd8fb48a632

Size

116.42 MB

Last pushed

4 days ago

Vulnerabilities

0
2
0
13
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:8-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:8-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:d38ddca084031a83f46d28122d51da3557a07cb32c82efa2e02a39557325b5ac
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:617a607a61d5ef5c4af7e2a2ca15c676f7c1ff7e77c05d286d7182f65928727b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:d077be2200260a76e95a8232eceb1b725ebf013e5840a24d09ccd3b00d6d1ed6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:65140425f9b5179aee8408dd8022f1ca444eabcda887626b36bee787bbcdddb4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/amazoncorretto@sha256:21ea907bbc9c8c454484b0c9e975ea2b7e3cb1b45beabd60b91a55fe87292a0a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:198376673f12a68ff3d4c223f61f0269c15d4d594b18164fb8358b3469780655
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:547c43e3d323a18a86966bad9f2bf7127545341db2f86cdc10703a86ed9ee4b7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:34960472d0d5af8081775ab4d4a21f56e0ca1e544f76a9ad15da04b404bd9f2b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:814e0e67fdc5cb44f738ad48c77008d324077f69b73d4c92f94885d6f4ad9007
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:7c301f0adeadedc8792cc197fc283d6d3dc254a38bbea5046cd2d26f343c5ca7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:79f1733a832b1c5cc328ab831f677d2e400a902053127581244fc958da91d5eb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:f50763990ed3e0ca9e8a4d22d3c283a859c5fcebb438023fc102eb806b7288a2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:f3845fc84a3a24e9edeacc06ae45d8b199f50fedb5e295296192b9ef38f1c0e7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:aaa6b97c54f789af9cca182332e37b1480927d1f7cee9b1ecc2d79d0e11a9ea5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:4143d0e1fdeb22ffd08b313822fa832b618754f20c96a74fd6f662759db5b5b4