Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 8.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

8-alpine-dev, 8-alpine3.24-dev, 8.504-alpine-dev, 8.504-alpine3.24-dev, 8.504.01-alpine-dev, 8.504.01-alpine3.24-dev, 8.504.01.1-r0-alpine-dev, 8.504.01.1-r0-alpine3.24-dev

Index digest:

sha256:31026144e5eed2dc8c632a11458f0a1336c4402bc360a1a1e740908238989f05

Manifest digest:

sha256:65b1928e99e54c48a83e387fe914262617568c4f90eaa837cb8b0786d20cb5e4

Size

90.10 MB

Last pushed

7 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:8-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:8-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:ce2bb0200ff25f10d9244b2794890c974bbb0f6ef18ef7ecfc01cb4fdd6c4ed8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:f8934b14f9c1074e7b629a435867233e0ca85d73411a0068502e449211932779
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:eb47ad13517463bd2b31aa513c003ce4eefe11f0e99e3b898858aaffd3cc2160
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:9cacf49b8c510dbab6cac49890b94061f1f8635067d9e76664f2d779292a4f25
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:1b62dfb767ba66c56e4669e14d4e1137f1809f2881251ead9aa3b8b2da847492
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:2c0a70fc02b67dfe9b90fee80dd3a9d6314f3d97206280c6e4a39e313ce71092
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:fc2a0758c6b5359ac61448006b82c70e218b9c30a6b6ae8fb1d82c2f2ceb8c02
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:5950de2831b4a8945382acfa2e24cf41862f1dd7ebf7eb4c35e66d3ee2227791
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:271e3a5ff3e7ed5a47511819b2f8e98d6258574760a2128157b7474ac23da2eb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:a515e0edd509637db668c82f4dd739e5a40ac7ff3bf22b9da6a27f1d01a3ff27
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:5e27384f9e2308466ad375bf9255efbc2bce44dc704ef635e65c4b5ae7245526
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:719bc317fbccc10177553cb604ae2870453697b54250f51368efd07c8ce05a2b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:d215247f055c282e305720e48cbfaf73dd747e60a64ad4684d520193b61e7746
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:a4d468d7e952c30491cd5a3bea550e575f52239fac902f3ede24a069a07150c5