Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 21.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

21-alpine3.23-dev, 21.0-alpine3.23-dev, 21.0.12-alpine3.23-dev, 21.0.12.12.1-r0-alpine3.23-dev

Index digest:

sha256:34cacdb0cf0f8384178b1cdaaa27caab04a49ed0c09f4c3ca756c2cd700f5312

Manifest digest:

sha256:2822ff13b4fdc9ef41c2dc7c0e4ca5fb8eea2d7b474116817eed592f4f304530

Size

185.50 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:21-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:21-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:3d3a3358498361550d572b03a3fa9df46549991252bb64fee385e797d90da97a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:663773b2b701872da417338e7af12a1e38d83e5ae9c0614f3145df2e4faa5b1c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:380214c155bd1c712d3fd0889879c5f665e84bed024d0e147e2be94d09216d1d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:5d4c8060afc753c50391e51978fac5a274f4a10b19949827ecaf1b2122283c8b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:49266025f8f0270c40cf116f0940f3cb901374c094c86f44747a61174ceae859
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:00025481b398c90ac82b3cda31a440987f45ed6804ee3ffc99c3b379a80cb717
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:2ec85807a6e43ddab34a23728d4c25d7c90033279bfcbba243478c0d0dface95
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:33772841e8bd956ce31fecd1c2d2d8ed93418808f5f09fa14c335ef8c33b0d2e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:9cc04d7dd493fc3494001514d43593e9e4afe91270a8fea25513aacc13c02589
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:10dac1a1c2e328d286c20419aa51a6353d84537f4707d66c37ce7ca5d29b2bd9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:fa8ab1f91a9551b5e670b4c1181677a57a4b0898e80880d26e90a6398d6f6146
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:d714b56c59693f57ed03b121aa138aca7f647d424c5e84fff9a9578eb6dcfcc1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:0dc805f7b693ff278662b0b3a5e410af2db68ce3224475c31a6f2cc6d7f54d3a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:104f42d9c62eee32957edc4fec6ca11c4ac3f3c30c7463bade26670a0fc1b646