Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 21.x

CIS
linux/amd64
debian 13
Tags:

21, 21-debian, 21-debian13, 21.0, 21.0-debian, 21.0-debian13, 21.0.12, 21.0.12-debian, 21.0.12-debian13, 21.0.12.9.1, 21.0.12.9.1-debian, 21.0.12.9.1-debian13

Index digest:

sha256:8ec2d4dfc549f71374682596faa433800f402f5bc9abec144bdb4c07983c2ac5

Manifest digest:

sha256:ad05de67b60623f3f4fc3577299016d0ef976268a09403a5bf2b40509eb841a9

Size

190.97 MB

Last pushed

4 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:21

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:21 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:659f8d19dead38f9726401bad91c2f1e9ebd6332f1a4c82ee7b95c4cb3adbd3c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:4bec3ffc7e275692e647e948d98af72ffbd2ad8284bbc90faa5b4a01ad8a3ac5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:c7154b3ecdc2ff16bee2ee1f9be1cadf561b90e4ae425864cbd3f415acd1f1b5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:765b3cae278c04d61b98c9690279b828232d818c1b23f643451d143d9aa9b403
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/amazoncorretto@sha256:f7eae2070930a2d78e0e246b1e69d770ca6639d2cc9a243ad16c6ca2d4762c2e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:eb0264617bacad620a8c3faaf5ae752f03c7265573a16fdcc85add56307f3a08
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:da2f1c22bfa12a501cfeb1b53d7f494217e993c2d678c03a55b4f6e52926e527
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:2a4c81fb969c6ea23e75cbd16e610007c8562c7de2bbdf1a134cf3de1286f612
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:b21fb4153992de40f94a81b6d528850a7ebbe682ef275143acfb22ee7276bff0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:eaa714c9fe1911bbe0edfdd1a78ec2ea3208bf6e74fcd6af91cf42290b9faeef
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:7b9b974075ea2ff9e2429c009c3cc172acb301330d6c0b6b44bf54e5ea44b022
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:0c90097c9bef125f7d6c2111640c246377edc07b6a2a649349fefecfe4c95913
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:7252f5b6cf2b780f7e652dcf08f4262613eb0946aefb1454ba60ec12fda08e29
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:525b75eb0b225ee6760dfe0d1bc273a45b1a06c349c21ffe9245038c0f50eeb8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:33c09cce33a27784f2368e3811bd9e790ac670f7debdb73a85e3a831c8215631