dhi.io/azul
11-jdk-zulu, 11-jdk-zulu-debian, 11-jdk-zulu-debian13
sha256:fa7343cfb4a4063bb69d0a9c6abff6e3668b0116f90dfee5a7ef01a55bf99153
Manifest digest:sha256:3fceb84b794a5dcb0bc7ccdfd24cefeb849cc868cb0c0d2b55063a2c8cb90b0c
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/azul:11-jdk-zulu2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/azul:11-jdk-zulu --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/azul@sha256:b9ef127e5d6876555e1d6e936728ee19a57fa50fda184c58af27a2ac68be1642 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/azul@sha256:436ab0cea3457b2ba19061148759e2e128f8214f288dd0548489ab0b38fde06e |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/azul@sha256:03a0d5dbe95d768d77a3b094fdb346bb53505bad922b8935dc1e1d4311546f27 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/azul@sha256:781c804276735b12c1007ca7c21d41b1de999824a398e5f2fe2d860b2f4bcf61 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/azul@sha256:6a60589e457462b177febe9639eb79637b03f3bdaa3ddf8170eea9d136698c4d |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/azul@sha256:78aa0b62e2ca6f18ad5dd8eab78c6530611b2ad35c67bd79d37a4e734493aaa1 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/azul@sha256:f633b36cc97bbf5fce2860fc4031a091f3a38425bdf03ea52189a043424a36b5 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/azul@sha256:a1bb4b1fb8ea5aa52ea62d20255bcc3b0b39d69e7fd31b166fd87c5ded8ad38b |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/azul@sha256:729bb87d613ac43ff1ff939674a676ebe00a71966f16fc07c8e1410ea686f376 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/azul@sha256:ca9cf8609fbb1061138cd44880b82393117d3bd0bdce01535b6b9275cebbf9a4 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/azul@sha256:6d3ef758809d368ec256efe1fc8a3c4d0fb650ba69bcff35200471cdec51a0de |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/azul@sha256:07c22a3d8b0ff5473e198072d9c8e1353d937c33f2dae23823d5ec9c6acc544c |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/azul@sha256:608460bac6628f3fc2e3b8b749adcde5f13099abf70abd605aace3541b7033b8 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/azul@sha256:63ecfed702501a64670568375b5587ab4f7bddf65f7428769e274d82b65c3e75 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/azul@sha256:cc37503c5b973c9d4c2aa283d192acc639e2f1881b1aa0aff2528826250b6c52 |