Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 8.x (dev)

CIS
linux/amd64
debian 13
Tags:

8-debian-dev, 8-debian13-dev, 8-dev, 8.504-debian-dev, 8.504-debian13-dev, 8.504-dev, 8.504.01-debian-dev, 8.504.01-debian13-dev, 8.504.01-dev, 8.504.01.1-debian-dev, 8.504.01.1-debian13-dev, 8.504.01.1-dev

Index digest:

sha256:221bc43301edaecd23a26707e477ed36ef21b698ce5c0f15594ae45fe1e1c26a

Manifest digest:

sha256:a501f880f36546313eb65d6773bdcf4d66eb8b01edb9e53ede0e8b57e10744b4

Size

116.42 MB

Last pushed

3 days ago

Vulnerabilities

0
1
0
13
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:8-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:8-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:96fd414743daa2cc49434b9a22808b86a849cc9a4599ada2c05373b00de7d2e6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:f87bf2cba0f24fdda2d4e4f51980894e84032daf8ed32c54c4ef91e11a2d5cdf
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:66327045f57e4fe2c19008de8027f9c011f2e274e32dc92ff7a33b0015fc4880
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:af206789f11529cbcaec3ada4a7d78673e9ba711df67b1ce8cd3afc058fab844
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/amazoncorretto@sha256:19927d801293499c08fc9449ea1eed35e07a86da05ebef957692ae2a5021c5e4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:f09e08a4e59cf892eec13e044f7d6814ee17447827a29ac8b60f68d07aa86b42
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:0ed1f344d5913455bfe01a62fdaf2ca8bfcb572d89cc4720186bd8574f228977
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:c8234627675a9d8fb399914388fc3df03f74c5ecdc24e85039d8f105148b511e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:7fc4f71278a52e0a8bf924074b8b45516857a202a79ecd83356ed290ecad17db
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:6eac724ee76d2c7fcf5227e02a09bb7ef334e99f228934ccdf85996ba678ccad
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:6bf4347d81faee8100c31e93a9175cb9866e82a66f70301366db80596d794b63
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:33fb4b3b89aefb8c66f2f97e6f500a1a02876e0b8a499358b8aad7ab0f279d59
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:291c4ccc8d52de0979eee19e6fb410f161def067411c9e9cca7d444c22a64a97
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:4aa82fcf96988f6988b454c683e4cb4ff0da86b8da85cfce924ef92e43f304e2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:09dba2ba5e5a54f7abd1fabdfee9051df71d04c18f526983206c9c4f42b95e76