Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 8.x

CIS
linux/amd64
debian 13
Tags:

8, 8-debian, 8-debian13, 8.504, 8.504-debian, 8.504-debian13, 8.504.01, 8.504.01-debian, 8.504.01-debian13, 8.504.01.1, 8.504.01.1-debian, 8.504.01.1-debian13

Index digest:

sha256:f6281151626c9d0e050c56c35927cd029f79175199a19255da1069d56f727f01

Manifest digest:

sha256:4c532fb49090730d6dc3f6edc524a152ef3ca1c0224e4540a97566e10ed9b5ed

Size

97.97 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:8

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:8 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:3d350a661e400857d0e5fba092c931f7836e62e0540296af544bcd1656a4f9fc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:e1350f5b5f4c36a9435f386ef96192ee333b4b90a7c1de07be21f07265815e16
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:23c09e4b950ea044b02f5708aa9827f876f959cb233eda816662dc3acc07c6f7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:e10885b7b74772a8932e734fb685ca455a6b91b834419b9b799c4152c5049d2f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/amazoncorretto@sha256:e5c6ea6550d53640079081f4ca777b96ef321477e1f10b9b5c9076654a741fc5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:c3bb227e4879aaf9be55f9a1e30f22675011753d59728c7acfb81c8ed75a6665
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:57815a343c320605a1343c3043e76661681c8424dcb90199e13a52878b22018e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:1889438a65c04ea49fb8c7f869eb31ce65a17ec916c942d9e641e93ec38ca02b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:ab6787d6181b9086a983b281584ff5243d40a157d4bcbfeb98bd1d619223c11d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:fc617deb8ebc569f132456af432dac102b1d577405a467e047c441fb87e45c86
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:cabc326b0c38205a836bad38b552255346ff00beb14a757a9de58b63d5e63011
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:dc214c6d25f29d59883e6cf92b0454a24df83d7857c887bf8cb43c646b1eef95
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:d6704eb1f035415b20dbe023e081b150ce966c415afcee4ca6372569a8a5d783
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:7c5d993394ab1797654eb085e8b1a7b1cbd1905f10737f4cbb7ea3e2d97825eb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:33f12faa9528cc3d615a1ff8e0a6a3590554872f9b366afdcaefa4a6c85a0583