Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 11.x (dev)

CIS
linux/amd64
debian 13
Tags:

11-debian-dev, 11-debian13-dev, 11-dev, 11.0-debian-dev, 11.0-debian13-dev, 11.0-dev, 11.0.32-debian-dev, 11.0.32-debian13-dev, 11.0.32-dev, 11.0.32.10.1-debian-dev, 11.0.32.10.1-debian13-dev, 11.0.32.10.1-dev

Index digest:

sha256:2cd85cad5e5e94eab002e12cbdf5ea1d3b85500aa8e648e27b4792982d0a69d2

Manifest digest:

sha256:1da59d2de6ccfeeea7774825f1e119ce681e47eee0a167276b9eb6f2d2d399dd

Size

198.49 MB

Last pushed

2 days ago

Vulnerabilities

0
1
0
13
0

Support

Active until Jan 2032

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:11-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:11-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:afaeaf2fab83f1f8d41d785dbb8a256e8c03b02fd464b42b4c2a48111afb7921
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:a0ae5aca294128ba8c83fd11362f472e5f1d9e3ad167de593359341555793f42
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:42adfed9348b41cff631c56da5d3118d6d78078d19a1d93b4e35f8192041b5dd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:554a02540fd1e2a20240b998f3cf78e787abf1fb844cb36a73ae4bca93e70cee
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/amazoncorretto@sha256:dc1aba1a7005f2a6c00d838d6d95699ca3dd0278f18df00ea517e2e562cf78d3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:45b44c5317f09089e5c82b70e44db9469dda38be8ad8351d95c2ff959e4d2388
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:13c96d620f119ad96dbb8f8f76a3aa521ef9b66436e1ec79f274416d964ce8c6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:167b666ebc073ad733bb5d5d6e50e002254d1c3fa5c2b3f56dadb7e37cac7adf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:e21d0e2d206eb1f66a13e288bb4756e8c6a75b9f47f95e8d79b257cb4f97e26f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:65c3c21f176e0f3c44b9604390a0e2631c1c01fe0117f17a6818020705703171
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:d03da63dd8af8140c1684fc0fc717f2258eba2bf4718c27480b99bf406b2cef8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:c17b72cb8900e11f2c6513c7260737bcc13139aa254d81c0d849acac888879a0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:f2c5af152e411aba06bb84d84a25fbfe8dbb808133ccd8486ea9bc59b0609080
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:17bcf2d0de7df6ec429b8136de6021955d0d30526ef40129a3c07acfba67413c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:0ad584aa38edc95f8a8523c29dd9bcb005eafb1be7f70aff21e64531a4c54f24