Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 25.x

CIS
linux/amd64
alpine 3.24
Tags:

25-alpine, 25-alpine3.24, 25.0-alpine, 25.0-alpine3.24, 25.0.4-alpine, 25.0.4-alpine3.24, 25.0.4.10.1-r0-alpine, 25.0.4.10.1-r0-alpine3.24

Index digest:

sha256:31c8d1abdff55b744e9306fe8d47d1c01cefef770f2a5873bf441d8f694d18d6

Manifest digest:

sha256:631587aa872223696f534a859d08e39ca4dd3cbb24c86159f7bb2f8caa52fb4f

Size

200.72 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2032

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:25-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:25-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:2ad48681d3f06ceebcb1f82a5a4a03bf65d7ce3bd32f1fa1c230ad5e33793d0e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:0a6b1255af7a36e8f06fbe6da0e392f6ef4279a5f642f335adaf7e993df9461b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:627f90581441a838fb7396f98306726a5992dfacfd1ac615cc3c9b7e3679cf37
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:2afd79eb347b6c8d4fe356624a9a4fba8e7409dfc50313a358ceac66530f8e50
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:eb7393cbcffc57074e2badeb32521c1cdeb878429a9379bd77e498ae1b1c5180
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:c82a271afea743dd19e120102bffb0a8885113b4fc5640f5df438b012c3a4b0b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:1a698af6001dbd50b45861a3e1970edf1fb55ce901e6d560161fd664cfc39aad
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:00689b936d55e0f020152627ffb7f3172b201610f609ee6816128fc04c81006e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:94583750a70e1afe28deb0b37f0e94cfdd5331b6382e2e79d567eaf6fec89a96
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:8e77f89276316c41b4eacaa10c1c344fff3bf1eccf90f8dc11a7d301f599b59a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:a4ae03e5f37feca7fa97c1af9d88bb78f140a8c2b63af7b972397a1b2d32c308
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:bd215e93e3797611eed1ea3e84e5731b0321a9fe79c058438e9fcd91b62a9338
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:2fa2935976cb62f50eea4d91441d230ed2cfbe0dd205f47c32265c186f757e4c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:66943602a9e964e9063ea1dbfb49fc93081ffe67ab919ce530a5a8dab1bf4cc8