Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 21.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

21-alpine3.23-dev, 21.0-alpine3.23-dev, 21.0.12-alpine3.23-dev, 21.0.12.12.1-r0-alpine3.23-dev

Index digest:

sha256:766d8361e717b79734412de731f2b4b17a6d30162168108bc31160e30e8b7d1e

Manifest digest:

sha256:95702fa0f597f3a592c9588f3ca386f0dd18606c31fea60f312a70f58ae550af

Size

185.50 MB

Last pushed

4 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:21-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:21-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:7be949af76a4d14777e7b4410827cb83cdc51e76d61184e7726aacf2555d62cf
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:6d07fcea43ad64a7a1cd158283b37294c8b456749a64b999aea262e3650d604c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:755ca9f4645b40b19ab54ee63032146cbae61ad802e471e6aafb85269d152fcc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:2e6c8fba36c7f1abc6e9718044a9b2c95ecafdbbde272a154c63644797216d34
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:d9118a4c9c6f9acebc201a97f35c293cb1047ab5943db9031ab9a473778516d2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:c2480b948b3591400ad3141a53b829759de070d8f6367d05a213e5be9da11e3b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:57e24f65580733477080d851ac7cf5d75e4bed48c23ecb59587f52e2db3fc0ed
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:c7fb267a65e7e0aeaa02cac5f2f7c81945103f61b54ddb04197b4113e1b02d52
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:77c8b25776f2fb1c339b509fe0790faec1544e19e71129ccaf0087a789b1156d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:977a3922f3f64218cf15878d9c42f9018f54eb9b0d737e8c940f7e1ea36d2f09
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:a0d6d81c76e048405763737e94aec53eef3af982a87b919ac48b274dba379d68
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:ff3cd8e480d6d085aa330e9b81b151d46e6ef11bea97815f55f4157a8e867463
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:2cf206e6b7157e3038076bc48c1ee9c4040b84a466c8bcc9e2adc6cb94c7a21b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:de01e2ef1fbfac54b34160add28bb5c0b7728e8cc63933cbf0e9b406618bd1e8