Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 11.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

11-alpine3.23-dev, 11.0-alpine3.23-dev, 11.0.32-alpine3.23-dev, 11.0.32.12.1-r0-alpine3.23-dev

Index digest:

sha256:c76c8b93adb6d192d1a5e9a6413b7eb88595b26f9548a2f238ad34eae0b48b41

Manifest digest:

sha256:21af52a91dbfc76226bb78b70de832e13c6d9c339a11d6d82a7ce449621d892e

Size

173.88 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jan 2032

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:11-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:11-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:6cdd17d6addf20527062f84e3dde6e2887b5941684ae37f7e95a8058af8e2fb9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:8aa60efab2fba00d541d8f6aaf3bfa8460946ac317e23fabd1611b63ec8da7b0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:96c30c64fbf22a13fb8bf14160e738b80a5d9353905c3813d024cb334ba5fd0a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:c09defe653c959d8ff2b72ac4801708d6f8ab517814190a3c9a3b70ef07f0d4c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:07c7ca7bd748b2cbdfa1328163efd40e3176bcd2c3dd05ff718a8ce169c52de7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:91e2471fb9ecaba9d52e155a945d8e535efb7cedb31b5d8f4672cde8e0b5b29a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:c3646a5fccf7be56057e5f5432811189b4a07ca33ff4f0d1f27031a889ba96f4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:d4e1a837dd77ba8fb3e6f4e69844fbb20a2eae8c1edf7a1a9b10cd7093cec27c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:6010b3c58f024f466721d4e524b292248c77926f0dd67598fafda97cc79949cd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:72b62184eab8c73cdfbc0c5c8f989b64f7cb0a4d535b27729bf89ee6794202d9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:e90e26003181b75c955bee34f45e5b6c0f1e7de17c2f8e1932dd8706a35ffc54
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:a7558152618cac00cddaf14deccdc4542d146bc19c862fc1586f351785af8e95
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:98b75b5187e809c44681c5b0b8e6e2a05f54ac896d92e88f642962117a255852
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:b0a3bad7df432d29537bfcbae1366a3b6a45765d1e301309387bfb58a1843015