Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 11.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

11-alpine-dev, 11-alpine3.24-dev, 11.0-alpine-dev, 11.0-alpine3.24-dev, 11.0.32-alpine-dev, 11.0.32-alpine3.24-dev, 11.0.32.10.1-r0-alpine-dev, 11.0.32.10.1-r0-alpine3.24-dev

Index digest:

sha256:03e283d1d9066764435122ab390a93d7dbb0d75d434f5c646b0a967509b543c2

Manifest digest:

sha256:6d3c81833a24561d33fb832e5255283627bc4e59678a3dc7445f258f5bfc8305

Size

173.88 MB

Last pushed

15 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jan 2032

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:11-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:11-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:f61f0e93b5e2fbab368382d1bcf189c519f4f107e5c06d1c69df19f1d90246de
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:29b3706aff3752d296e5352b0a0a8456c9a9b79adafafcef1e4b64e05310d775
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:50088af626574158a085791838a358a34edeaec925baba2b65e9016f2e7586e2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:9219756bfc7e6e9689af9f292c78da170548d2ce750a13b23dcc72735c89d422
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:ad89456cdd620eb9eb4e7ae1fd28904d4770973acd2d2cf0903c646a268d8ee2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:8abc9edb1fd43c6b80a0b75a492b921d79e9265f6bbd2d0bb50220b4c9dd7ca4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:85306b98fe83727a55a71876f6b70f3fff2975de75653536f9c2037776b41218
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:18ef46f46777385ddcc566a1b51f2aab8d16427102d23ce1f7d5368749a12000
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:ce4321a0f2050062d90b61674a984520e3c92147ba3d95dfcf47e5bd6d62f2da
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:d2a8a7d1293e3bd00e451e03bee73ccb972a9d0ca95c0e675e430e7615f4648e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:e3df8c7ac727c397162cc8645c3b744a0a3c10674a0e18359e9f70b2ff05e1d6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:26cff09b51328d0168f0168d259f71921004603f46c7a79f2c1af1e097330aa4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:f619552f51f1a41f9e3f339e648358f7d68146a6a0ca545e00e9ae8a09fb56b8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:60f8919fcd066b9bac33985aebbda9f2a0a0cf39ebaefac8db819de57d9771f1