Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 11.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

11-alpine3.23-dev, 11.0-alpine3.23-dev, 11.0.32-alpine3.23-dev, 11.0.32.10.1-r0-alpine3.23-dev

Index digest:

sha256:903e275aa1228bb373772ea840c2d79af0285345c64f48c7bf6e51d324ddd198

Manifest digest:

sha256:246069aeddd42b1ddc5a485fbffb0f49fc5aa46c566fdb985b9daa32dcdd9ac4

Size

173.86 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jan 2032

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:11-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:11-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:1b60bd8f80659f59a4537017ff2bc013d12c0570ec98fd66f1b66f6ada42aee1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:29330aff57314c88324dd72a62e041d78059931b21680f11973b9b718910fe9a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:18545fa0174996f852d747c75e05c67aff98bd5e284678b90608ac04c10e07eb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:f88954a360f2fbd05ae04f002418d51cb0a8cf68c9308c565aae90b150bf4f14
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:b300b154948cd7269ea9469533a258c5f79ee5932391e04619a9c00ec25f2b52
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:9ee5abc50ae3945b3f085f4429172492fbf6c5afd43e400ee9039b09c8350b51
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:e505f90055255da18b4f527b6ac15db7b07dc1efcd3bea488e7ec736d1d916a1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:587975d3783851218f4a83c8cfd74b370a29bc352afeffbfaae7d6dde24779fd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:075774f6c3906de58097d5d6751e87186edd017d2376b0f154b603c5ce0ca433
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:40b8749bc761e8c5d49914d3248365a7c69ddaaa930bd731301eefd36b9ab622
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:03ccf1493857d5bcc33e4eb43fa7f22df9ac64020fbc8360f84a563f3460928c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:868942556c61bdb7cf2e1405e30b64a7b22dffbe021421b5ba1611d32de65e19
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:ea44bcde965d1fcacedb20a877d485d7c8269d18f2c42c44bfd358503fea0221
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:0957c00498b3d4a1590864d87bca5244f880f4af4b1872c46b6373badaf0116e