Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 8.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

8-alpine3.23-dev, 8.504-alpine3.23-dev, 8.504.04-alpine3.23-dev, 8.504.04.1-r0-alpine3.23-dev

Index digest:

sha256:538b1d58d66be23b7c0f02ae3c70670d2ca52f159c6024c0e03bdf67b739e394

Manifest digest:

sha256:c4cb8cad131ccc8cc9ac6b0f8dc2c3ce4b9ab4365fdf49479ed2bc00b5a8d78c

Size

90.07 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:8-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:8-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:1268ecfec0ec3873038b0007240b19f7288fe60514ba7340a7914aae4e92b5cc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:3471ca25376ba09c0d6544fa05014c69392cb86af67c3149c6cff658c9232e00
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:f47471c553092420406136ab103ce8f9ae3a5c818da50828fde8c4850b90db3f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:6877dd761930c5e3dfc33ed07f61843a841b5a785b8dd83f7b83505b3352f83d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:2f85f9bef575a71b5321f4632ffb1217382ef022e77dfefadce266e13ae74b62
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:7f40e6b7b9604a77f4797cf3d6c5eef79b2dbe6b27fa1c7acf8881677992a5e3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:85963028ca00a4cfee5c6462fee7e9fd874a67457a87caf81b409442c2e30b2d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:56a204f14d3b97da0facbc546f762ef2c4526a44bc5b1c7a057860617cbf5a5a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:935963288149c87c7f26cc39fa9b523a5098c65a687ea2f26e6bdb461d30e625
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:a19c871ecc1f8ebae16b3a76301f0549e5ae0f8d1789282520e975162cd4f0b2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:03a0fb64fa0e5f2174f13468a48b52249feb749b7f4276146a5b9179ef1b2f62
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:2ec0f62eab9364632ead282bafacb795a7f483e424fd0c073fa901741f6c6731
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:73a9910921beb5052baa86f0599d9b86f47120a6f25f7ca3d29aba681be86faa
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:a77ac5e190f3f61775fbf5ade8649111287d4d5808aa7c089ffae98bf3a1093f