Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 11.x (dev)

CIS
linux/amd64
debian 13
Tags:

11-debian-dev, 11-debian13-dev, 11-dev, 11.0-debian-dev, 11.0-debian13-dev, 11.0-dev, 11.0.32-debian-dev, 11.0.32-debian13-dev, 11.0.32-dev, 11.0.32.10.1-debian-dev, 11.0.32.10.1-debian13-dev, 11.0.32.10.1-dev

Index digest:

sha256:06b252a11c64f7b0ce9e928b4a89a7955be81487303eb871f406f28430b3676a

Manifest digest:

sha256:7d16dd5805f12bd259ca5dc2ac31d3078c48cdd22bee3a5d277091e6670078e5

Size

198.49 MB

Last pushed

22 hours ago

Vulnerabilities

0
2
0
13
0

Support

Active until Jan 2032

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:11-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:11-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:756c0919e18e91ec458dfb71072c9247f00361903d19cf858ddc31a9fd40f23c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:928f5ec5cce0bbf7ad26959864754524e3f417fa2bbf96ce3a7edaf7bf8a3a6c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:4e1331e1324bbadab963517430c718b4b663a05d0e5e2553543071c6e6b8493f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:b6732ee163f6a49ae4c8bc760bbcbe3c69efc9aa276cfdd407e4782b69b52516
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/amazoncorretto@sha256:3d670e936e7f0c81572bccdc18337d61c207553d0d2ed9f0e2e850f4916c96ea
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:9c0d533489b1ea6b838ecb6f54d037ac74ad16296d3bfc2179ea685c61e0d380
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:ad254aac8b105bbc442c18dfa953c7f6e3c6b68464f9d0dff7bd2733bbd22164
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:59e7f32b71886249a318412e613f9891fa0b47b10188f86ce2f19588d95b3715
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:bc2bc07442149bac74d36ee230e59af585c8f2e56630957565ca728cd6d93832
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:5638eb08f019b3d3c38011d90cc7aea6b4534fe00c9e9eddeb3720eed9d8999e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:f8e19649509e09e5077d1c399a99048de709279ba6a51eebf72af17e85cf4327
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:b771de56d579e63a61d51f5c0b347c79cae92599a3bf9cd1c6691fdbc25a0d92
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:3e1477fa0a0e72be1791039723ab9f12f17497bd0bdab006646cd95c161519c4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:78c5fe50f0c2924cddd4afb58e94421b1a9658a3077cf02e58521d65f76f96c7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:b31d7eb30b9aa3f08638ba2ef0564ec50a7b8ca77f99dc82b36eb49f468dacc0