Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 8.x

CIS
linux/amd64
debian 13
Tags:

8, 8-debian, 8-debian13, 8.504, 8.504-debian, 8.504-debian13, 8.504.01, 8.504.01-debian, 8.504.01-debian13, 8.504.01.1, 8.504.01.1-debian, 8.504.01.1-debian13

Index digest:

sha256:d0ed9f29d2d14fecc6ed799130f8d37b4e6f89fd32751585112c00a4930252b3

Manifest digest:

sha256:8236a18a2c5d6414cf169ae71483902d387cfed91385baf3057ef082075eac6a

Size

97.97 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:8

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:8 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:46f87895f63dff5e27dbe05c6b71d1e24198fd486de6fc753777fbd6558a90e0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:b092ce8def87306c85329c86509c7d79c995e43529a31b7cbe8322074db57c5a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:7ea5202fd3621c15a27355fe89ea366e79cbecba5ec6ba641c0a9e0cdc0ee168
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:d31fd865ec00497911a0f1a1fa12cdeb6fc189d1ffc3e2206e80781e24ffcf48
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/amazoncorretto@sha256:91645f5a26a7263b8f6ce1ff2cc77ead866c2f06231dafc58a1e6725235d6796
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:de35f1ed0d3ba58127502ed5ba55cc02677c59eeec5a0912f324f28d5da8d4c9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:5f3bd2bdf8bd03e31ac76021abd9d224f81be34a801229604f2e8f3685b75711
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:26aa773bd48c9ddcba1bdee07799458ceedfb2be2bd698c8cdf4aa23a89bb206
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:e755c71302d61fcd0bb3370345dd17f38f9d50bce60f0fb3431b84e7f3985609
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:14c728c4f80a0c7c6347cc214a9177a0f07d325b6e9ad5697ba8095e42f5c11d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:1518c990042162402c90aa881cc56c164580c1e4587ae1854b07edefcf400006
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:c193591f78246614b8349933269ccff923c28ee53001dcd0ae0037e243940c80
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:4cd6700ed99d323549d3bd018976fb6b9c23a85914c589637b1ea3ef23ed9997
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:71bdd436975ccc2fa7ab874b12ab59b35f23b5c6867177e943090feee8366a9b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:87615e42ff3cd9431f8e366e7d875c08e302ce19d560c60643a4dd038cb8b887