Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 26.x (dev)

CIS
linux/amd64
debian 13
Tags:

26-debian-dev, 26-debian13-dev, 26-dev, 26.0-debian-dev, 26.0-debian13-dev, 26.0-dev, 26.0.2-debian-dev, 26.0.2-debian13-dev, 26.0.2-dev, 26.0.2.11.1-debian-dev, 26.0.2.11.1-debian13-dev, 26.0.2.11.1-dev

Index digest:

sha256:6e2f47c3f88fee664f0f1e937d0cfb14a92e7830441d4b8e42342cba38dd2621

Manifest digest:

sha256:8cb10ada3d4251e9a024732df9388e770d760992b434a8720a27661202a69b50

Size

232.02 MB

Last pushed

17 hours ago

Vulnerabilities

0
1
0
13
0

Support

Active until Oct 2032

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:26-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:26-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:8c55ec49548a274678c3f82defe3843cc694deccf08750ac5dbaab70c961ba80
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:69eb1fe684d219496aaf58448e6761407c8dc3a92c086fef072b0054fb6ad14a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:97f181eb76bea48e5ef9cd4c41922cb411be149c2560665a19ac6201d64ef125
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:f87b4af40ae1a4a25857d9241a1bc07332e689416c48153986a22612b6010f60
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/amazoncorretto@sha256:2ae26d0350f6e87aa5a7ac1f29fa966b803543851d0b429400d102b5740e9a4c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:af258d3b1a3bbc0ff8300782d739f7065030d8f564650cdd7ba99347194e107b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:638187dc1e8f3dc940c52982f1eee38e987b969253e11d91fd25a37c374220f2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:777c85ecba8175012ad2813ceefc91eec3041f5298293ebab2f31a2c1be4a16b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:bdc72745ef09914d2e9b8b447946970a61699faed18d60b55e47ae649fb48b4a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:79d308ab2c7a80531f174377228ad65dbf3a3bb8ae147467de5cfc2878c4a820
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:f3320f4331e2fbc675f42fb5c481cdf828c0d58bac008f227b15857c86281a7a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:198f671e6d4e5e90223d0991c81f9415d8c8b561ee5cfd2ec7daf983bd904d7c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:244f606af3710d90805c2d3818706bf2130d1f45a080c3e5889a6a44d95c6df2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:0822de8d63763905607420fc95d19d0381e5520842c997b0466d1f8bfd822246
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:3c808d599d2bb6f7f33c312dfcb4c2eefe14f1bd8cdf1df63813483167ad74a2