Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 17.x

CIS
linux/amd64
alpine 3.24
Tags:

17-alpine, 17-alpine3.24, 17.0-alpine, 17.0-alpine3.24, 17.0.20-alpine, 17.0.20-alpine3.24, 17.0.20.12.1-r0-alpine, 17.0.20.12.1-r0-alpine3.24

Index digest:

sha256:a16063ec11ebe55de37fd770f9ff08fe2987a6a52ded32ac7ec361cb6eb97859

Manifest digest:

sha256:48becf90793d1ff7f08cbe8521a76b2df1d4ac7811f34c9ffdcfa80e21431809

Size

170.82 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:17-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:17-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:f74733cb5c1ac343dea694b8701f0771d72ff7223d284649aa25a10eeb1625b8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:b3430a92089b38cbea304587f57d68d64c61b46cd27d85a376d8887de3223412
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:d68d1cde89f15058f33580eea40e62a7ddc68286e6420206bce1fa9fcfc670af
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:f44a8ab918f8ad0d87bf58e1ac94f16b630c3a7f4862cfe7ec0f852027c8fae3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:7365af8886886b6a940fd289c4739367a269dc578698f3b37fdbcc4d86ed9109
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:547cf6fffcc57fff3ae1f91b84ae3495a506d428ec217a6b5c9fd0d8f69e03a3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:e0a9f8092a168aad3e751f72d6b77e154097dda70342691c7c4d4fd7d598d419
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:83f5a7a7ce1c10e4d3b7ced3c4b1c0401fb3efe3d30278c9f7ea64b701629483
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:81552a651b0dc39826736ef6262b369d104f18e9b9ad176c8f2a34fa9a4f1a07
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:346f85ff85aca59c2a3109875679623e3a3d8ef5e306a18e1685233b80309948
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:97fc78621b0eb7c6d0e94b667169b4340792354bba9b49c7d9bc967ac04f1723
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:e1bc17d9557eab01c16eaeaeb240c6adbc78a12392ab6f193cac37f891c186d4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:b84da966bc879bfad65b2bc322e689d398a37b10231e28b1934a21db300b89be
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:2554670112ef00a9446d737e7a8ec7341611b0b55f1c3cf583268dd7cbeabe46