Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 17.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

17-alpine3.23-dev, 17.0-alpine3.23-dev, 17.0.20-alpine3.23-dev, 17.0.20.12.1-r0-alpine3.23-dev

Index digest:

sha256:7e84af2c443f3ce339887a3afdf47638d574916424b8e6e385e134b6df6f3064

Manifest digest:

sha256:a867984ab5203fe86899026b3414c53756e7b2df29ea825756e467a25415f487

Size

173.74 MB

Last pushed

5 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:17-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:17-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:4351131cba03bf839cc4f1071877a4199f603f04945a67d6d7bacf2de2caa69d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:e8e26b21bcb31f9b1c248e40b8fadaa5b28da344de354f69ef5c0c2fe31facf2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:d3cf3c199ad7cdaf6e1e76e79d5f5cd2030b901f41dd8d3aaab0919603f4bcad
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:e16d25b7b7cbc456fb04db137ced87c770639d0c5c27b1e83a109ecc71c26306
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:3c9fbcb097700c5ea17c1c2365333f3403f7ed05898c6829933d9118f4d4239f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:50042200ff391fd6aeb6b018adf4acfb07a1caf679630e5415b5f39f00bd989b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:cbe163feb6d12025914f037d0915b443ca0b4f1a4ba2d06ba6e522fbaaac775d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:7feeecf7c1aa063d86545afca30c6a706cb737435a401fe01321dbfe717b74b7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:779744a581c5cbe25df2401fe4cdebb0656cfed39f58e60acb4e494651e984dd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:52f7ae9a263a3596a9b0752261de15eb81f23f8152fd614a468e5a04c0e3e63a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:31ee0c8bc228753592174e0792158c4bef3f8a4127716ac094e59e1cfb85b4c0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:e582785a968407edc7e3cdcd825a3e647203174ed82dbbb5e25e978c1d641cd9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:db7a2e27a865924cfaa5d08971603a80be94ea2549dee6c13741283f0dbfff3f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:9fb47cf0464e741e6affe19c70803c8e4a4a8146a7d45dcf78db661a3ac0d58a