Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 21.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

21-alpine3.23-dev, 21.0-alpine3.23-dev, 21.0.12-alpine3.23-dev, 21.0.12.12.1-r0-alpine3.23-dev

Index digest:

sha256:8df02a01082f087cbebe97b6412dde2066078ece29fc4be87d59232d1a0ea8e0

Manifest digest:

sha256:b480211d5ae4e67984c94375b53d9d439650a6af1f2916606992c8d07397050b

Size

185.50 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:21-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:21-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:f0cb9ebe0915a0e3e92904e33a61781442492cf5bb9be55a98381c432dd74da9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:080a1c1593f9556aa9844a40addf4a2fc8a714ff182f60dcce2c446e0fa2318c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:1109ff8a466af30545749d15a219677548c38d8ae27f340883a00e4493c4e0d8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:3526d16dda8904345156764f40889e7ece694048496edc18493c7051721c0a7b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:942b6e53b4af3f02cf69b1a493e608fc6d75c48d96e0785b88f8c287ca0800af
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:081c7e11a36be9cc65363575a320861fce9903d3e818e1bb8dff0405f6e3fd6e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:7bfc197e0ceb9a3ab41d56ae3dbb820e9af3f7d3607bf6f845d9f3a264ccd065
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:f80b50d693caa9954db7b6304b5b91105aee9c7828b284c960008bf99aacd8f6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:ee56d17b4a42713f7f6090a4214908343699f4691f58a059ac316451239546df
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:dfe2dcc7e2c07b7b073e43186137923f3eeba2b32f7bce90bcea154b776db416
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:9da91a50c917aafb6f04a5692cd1210a29f638d67e7585f9fa8ba4d7ff16844d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:7a5e8676632eaadd9746df4daa317f223544234d360ae874708d103cb534fdcc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:cceeca760e9ed50e1359df7c423e4c2c89bec6b37fbd0571fe8d6e77b8503c25
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:a07f913761ee7a2920d7c37ad86eb7eba3ef7f271fd0b9f75e8863120d6a7910