Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 21.x

CIS
linux/amd64
alpine 3.24
Tags:

21-alpine, 21-alpine3.24, 21.0-alpine, 21.0-alpine3.24, 21.0.12-alpine, 21.0.12-alpine3.24, 21.0.12.12.1-r0-alpine, 21.0.12.12.1-r0-alpine3.24

Index digest:

sha256:425951c5f1b9700103be5683f623fc642bdf82cfca8c56dbbaff49ac13aa9af8

Manifest digest:

sha256:5e8ce2a9747949b622df08245320da868a9cc37bc6f80f2ef1ed91a0d6cd6b69

Size

182.58 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:21-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:21-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:2064a8f6dbf3f38e760ba35c33de2b832d93717b8876a91aaf5500a8ada3bfd5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:c74d19d4a7807884d5735b6e0bbd2df63122cf502e94e2dd0438fec57ba6d75c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:f9a82eb86bd442496b1e3bf6a3ea486881e8b6834033ee29b15a09d655f77e81
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:bd4edb685081a98595b765aa9eed13ba190bad9db9483cee27c95df976197402
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:a348bb8346fe4c41f0b5fc04692e57be69922ba2d1003262c83919baf3d69123
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:e26512656cafd6d5d4c1b897dc4b453b1b98814fa9e384dd8e29ead7e40f89ed
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:77e1b536b822fd24be82efdf7bdf6221908de122d3382d75ab5d6803852346e0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:f7178e781d0d63a80488cb8e74885824a4d39507ac720bb2469902c7a6f13da1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:f5917f02fa9eb625d394b0941e3751e7967220b4c1a864161fe6a680f3b14cfd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:90252dcbe7842c91f12a4c6b713d9d162a0b7b536cde33c283c48d2e49322fc8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:b585094509e715954d50259715a37fbbff8060b2bb0e37cc5b07543bbc266b55
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:3af7fe320eda6e81ddf68604422be9e1039a19c69af54d8c5f7799f8efd2bd3e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:253102c4560d71ec23368344860b4b1f5e6d0ce75e28dd8149d2055e90fc20d3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:311de7d08e26498c5de7c93eb680369619ef9ff70182b66809a31465da809b0f