Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 8.x

CIS
linux/amd64
alpine 3.24
Tags:

8-alpine, 8-alpine3.24, 8.504-alpine, 8.504-alpine3.24, 8.504.01-alpine, 8.504.01-alpine3.24, 8.504.01.1-r0-alpine, 8.504.01.1-r0-alpine3.24

Index digest:

sha256:81c3a5053c4c065cf64872f35655a3878a82fc03b01f4a6e4554952de0ac4eea

Manifest digest:

sha256:ce9878a4f1b023b97a642d42079e2f8061c6626b54f424cb5a35dc6fea94a828

Size

87.14 MB

Last pushed

14 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:8-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:8-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:6fdbcfe2ec1ec4fe0b7bc0d513ef1c58e8491f57fecadc3f19cd385a94822315
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:0ba4c7b439cda495fe3bcd9b5b9d0a146fc1fa2f123a127fb4641a8e6561add0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:f75ad7797c875ed16ebe6e360e1621b17fbe4220e18b11b0ed096bb0259c9104
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:440724c546a70b0864740dde745b7c645add9caad106e163f1a5d8ee33aeb4e2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:0e86e42d218df2bb7635c236c2ef86ffe49403a5f55dba83324df836dfd42025
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:3a20aa3281a9d53a489e538062ffe58546b19628f399aae2c9c08ffe0e34c887
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:b17efc47bd405759839ff07b7a703530852d196ea29580d2ba4e209a6da60dbd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:2ad555a4125e1f1bf5cfbd01e37ddf2ff6171974253dcfa91b2f960ef38b0acd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:9c2cf47b4a878baf6cefa95832b062144afd0f9262a7eadef9609df0d1e82862
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:f392fe9db52a4ea9f4766c8e912a549caa28ffa3bafbb437911aad051fdec654
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:072e4b69a7cc1407a589961373af24d25cb83002e89d5b6cbed2eb4c3d184039
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:4665276c3c2935eb641e1c43eb608bcc57579c685ac0fec1c823e0d3ddc75006
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:e8ec870908c40cca93cb28c13610ec320a676b144e362a73f200bcf948227ac8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:ef462986c87d33ab224e375ff4121882ea0ee8e515cedc2cac2357a6b547ea68