Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 8.x (dev)

CIS
linux/amd64
debian 13
Tags:

8-debian-dev, 8-debian13-dev, 8-dev, 8.504-debian-dev, 8.504-debian13-dev, 8.504-dev, 8.504.04-debian-dev, 8.504.04-debian13-dev, 8.504.04-dev, 8.504.04.1-debian-dev, 8.504.04.1-debian13-dev, 8.504.04.1-dev

Index digest:

sha256:2ebdba004dc619373dfb37cea13521b8658187a2b3e0456a7f269d69ef7fb5f4

Manifest digest:

sha256:3555f637f1ff633f68c6da041ad464e7f363b4d8b2b75e42f57c54c875a3cfa6

Size

116.29 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:8-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:8-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:a02e2ea61d4a276770142ff039da5d865671c21f6f5be457f97d03165d873717
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:e2be82ec6d0d2ad31f49504d7020d7fbfb08a42ddc84cb93785974f84a0ae62e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:0a7045fa562c37aed462dda45967ee50a919915fa72cd59ea4d3c3d0949e149b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:1454ba15ceed072377778bcb32a024ae9325a940a10d696d8d7649cd9b44b989
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/amazoncorretto@sha256:a13be72cd2abc558d69dc27e0c6bffcfd7903d13df48308f1b671a08b4e8dd7b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:16f619bd487f9dc59cfaecb6cba484899f63bf10e2c45f75d0284261ca4af469
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:d60920364685ad344a4a6c375658f6cf155eebf0b404795e8f0a00270b092672
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:d1bd4e08d98262f7d743a99b6c4aaf0e5d2ba3f7a4ac70ed8e5c271af9c85939
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:b2a6063512bf733b42c1fa4e6f2c8d9e44e0cc4016110df51fc17921ed64905c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:ea13ab82a72a568d2bc54f7ffc78ef333dc773306781130e38cb33a8220606d3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:4bd5544aa41d12fe762156c4bbe796939e477818039a7f57a0de35b41f03ed74
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:6794f032763a89bc28eeae4b63a76023ded1a9438434bf009e419136b6af1658
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:60ee067631dc3f331055a0ef263e54a91fc23cbeca3457ca4413dec2fa88b850
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:ee19f76676cc26877b7fee5c7fabf1545bd1809a840b2b8dcd6d89c021f0fea7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:7b1b3c0bacfb79daadc306e799cb8fa8812791b005ac3d95a7cd9fe70f6e66e5