Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 8.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips-dev, 8-debian13-fips-dev, 8-fips-dev, 8.504-debian-fips-dev, 8.504-debian13-fips-dev, 8.504-fips-dev, 8.504.01-debian-fips-dev, 8.504.01-debian13-fips-dev, 8.504.01-fips-dev, 8.504.01.1-debian-fips-dev, 8.504.01.1-debian13-fips-dev, 8.504.01.1-fips-dev

Index digest:

sha256:8831207f0130845c8eca9c3b45a9f77ea4d4298619e4207bed5773d3b2ea62f1

Manifest digest:

sha256:007a4ad42ce62f0928586377a37088b8b9898f3e030cc511e864db871e0e21c9

Size

126.55 MB

Last pushed

3 days ago

Vulnerabilities

1
3
0
14
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:8-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:8-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:78997027ed8bb8a5c380bd1f920f90f2388aa4600059307957e4237b6624f557
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:77314734b86ecab3fa9acc5aa8d7a78b088372956d853de1b49cea0268b5cba1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/amazoncorretto@sha256:d77c65e8a820aa77d298a7d17dbaa2f4b1a223ad3d2688559669900755d0e023
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:fe5cf39d65c390e4f6beb4eda17e481761f40c4bf0d973db0b93d0f6fc433ada
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/amazoncorretto@sha256:d56f66cf8b18b29357ad63d5cde7b0a2946f3028f88c6bf6b053acf2a5bc7280
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:933880480eba522c78dfed51773d5f50ea6db8321883e782540421f38cfe795e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/amazoncorretto@sha256:d3140462589d6fa7dd9b32897f4c6e7d4ffd309f705954ee5af79726a41fe27b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:4a41b9088d638eb6145557d52d2ba55e4fcc67712138dd65fd1fc842ad6e3076
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:9152c88cdeb61b533383a5a2d23f09452279e332ec47a0577aaa9573d0a2451e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:a06c724d00da50a258f46bce4a87e75c23f6d40ee1f0ff0df80bf81455ef5395
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:882ac1287c31c9f30728aae755618e21450393e2a57b0aa9c2198e8ad55f4f8c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:e144e4752f6d874f07d0f06f1362c00357f25ab85570f3f369dd9494a9fb64ed
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:f06c68fb2102b6c57b1c37caf6e8d79765215bea3cafeb098c88a58f8006e5c8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:141c2358f52d602502bd2c54fac96c864f1fb4bd9a9e9f44e53f9fbc4c010486
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:bd7afbb140cf31c5954eff8eae69f7a5a800d30a1d320003c064b808eaeb1ffb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:3957188c86e942a3e47f13c246f393d7111d1dedfab9670197a479d91a42fdac
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:b73a35dcf47984be5ee4d5972b6fbde4ea2ed899ae176f9db6c783bcd7aaf383