Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 11.x

CIS
linux/amd64
alpine 3.24
Tags:

11-alpine, 11-alpine3.24, 11.0-alpine, 11.0-alpine3.24, 11.0.32-alpine, 11.0.32-alpine3.24, 11.0.32.12.1-r0-alpine, 11.0.32.12.1-r0-alpine3.24

Index digest:

sha256:10353923f14c7f67c2ff0b503bde786a85d0c6143a33e928dfb82be405905bc7

Manifest digest:

sha256:f5a559bc9f7d13f3129fda83d33f002a619b0ed8dd97d5a6cd0427c8e62a906e

Size

170.96 MB

Last pushed

6 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jan 2032

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:11-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:11-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:1fb1c343c5b5e8e705c64397b602d5e304caea5791ba81d9c939a8a82a0277fd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:73cf1cfc8e6080c1f06e2523459d1736445aef5970f4cd26609af8d427c6b19a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:66cfe198eb84cee1270f7e74b31a3679e27f54cf566ccc2f5c5fe380dc3d3f82
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:ca0885c914c630522c8b5e302b7d4439ab0a073d81838e120867b0319ce4b573
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:3209eb42e0cadff52385fd44d060b362882c511216a5f654c81fdabbffaebec6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:c4bc5ed2256fbce6ab9ee9d6dc9dcb13478e00f54044c30de90e8565fdc03ea7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:84fce93ec764514eeb8f2aacf7999674835a32f5d142065be97745bcace9961d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:e03e0bb6327289d03dc6813708908b3ea685edf10f97a8ab5e02466a5e77e4db
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:97f7b0be8ea2eb9902ee4ff5be6064ea9b58774c38740182f399c3ed7d5eed03
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:7d2f1caf596919ba27ad2f30ae571ad95e7da30f1271e131c665bc85590326a8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:615068a523f024cd51613401a29f4088dfac5f7ff95c9317a9607affb400eab8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:60118b8768e58c0317e69e6816119b15d37c605b658293a3bd0f22ba576e2be2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:1dbb0b6ebb1e58eb847d691ce1a9f463c19aa004bcc45d2c1034a89ee7a6f42d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:82a303330e2bfea04d083d0c7db490f2f59caa9d703b96ed62620d491cc08130