Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 8.x

CIS
linux/amd64
alpine 3.23
Tags:

8-alpine3.23, 8.504-alpine3.23, 8.504.04-alpine3.23, 8.504.04.1-r0-alpine3.23

Index digest:

sha256:ef9abe53c378bddb20b7ed02ab8668428e38c1e820cc725e7254580f99202a34

Manifest digest:

sha256:031239fa02c1d1b2f017a6432f261b33b25f7455f116ccd27dcefb7fac1a0abc

Size

87.13 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:8-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:8-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:a5833da36971b42cbf7bcfd0df37fe825f8f94aae376ee94b0da04688416a97d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:6e139ff4da6bd4f18f3773aaa74ed455ea8bfe618ab16c6278885176ec8b0b83
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:653d49a0ee65af7ed17f5267a1c4170afdd4072de2bbda5cdd64b6b64cdd760c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:6ede5d5e095e4171d2318275cbf5f4ebea0bc67a4f671614e5ece7bc99cfc5ec
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:3465ddcae48b3f00d4f3b90fc6a0881782e81fd78973709a8792d533f72cac52
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:d71655daaacc459ee0e92352f7923967173975b1b9f59f3cce1338995bff681a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:930ea6cf621f16d26fe860c2daf600a2ba695e86fe813ea99247bb8332177836
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:fcbb5aff52e44187e554dfffaa7ec267a760fbb2429b6edbb2763341a17ab2d6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:201d2d1f3c3dcf5e8a2a138eeceff6da005c253d583c9b9ac204676f8034eed2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:1c083f56936f45b66a3d305e5974cf0fbf53152904b8cb36dc5e1a2f61df5820
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:b5955a98dc027d645dc11e2aa53821442a3b532dc790b02f3d178d29ba5458f9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:3db07cf5537b448145b752ce749ca850eaee3765105ab8557907c6f0db98a7c9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:8fed5b7c9024a6ffc10cdb50aa55bc2885c8d21bcd651b440c2106ebce67c440
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:83456ab62830985554aed9c4e9112863c0dcdab656dea36b8f3bf1872bce86ec