Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 8.x

CIS
linux/amd64
alpine 3.23
Tags:

8-alpine3.23, 8.504-alpine3.23, 8.504.04-alpine3.23, 8.504.04.1-r0-alpine3.23

Index digest:

sha256:3d225ae46ae961904f43ab36556ef97bf2a96b57771c65d53f364f3867107179

Manifest digest:

sha256:8fd3c7dec74ec9b5b4afd2012ac83157a9d9e33fdefb933d59684596f6be0f2a

Size

87.13 MB

Last pushed

24 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:8-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:8-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:2cd294641c99e644fd844676835de92ee240d58160ae056915be0d852371b7ea
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:2d57f5d70f27b705f2c3ef52adcd2e2dd6da587e0eeea74b6b612f9062288270
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:1d6fab8184f45a0f93c2ade41f54faad7a3cd723192e8df16d067c7dc83450ed
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:8d7dfa0bf8facdce6d6c1cd5515c35835a0b2d58529a84c2ff80af6b7af8f7b6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:62308a3e3f3596ba5556ec97b8e6ae631943314ad91a457dcf83096de462e785
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:0db4a32da5cb8b0a3e1f744942729746cf298f4aa382bd369bd355dca6703991
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:eed940306eab1b63889bebb9039f54382e4525c8c01dc5198565a77aced67e45
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:2354fdce67497a5fc2e9fa5f4bb985c8987f4f3471d4092349e0fc9987adebb7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:d84e78f0646676b156d824346e41d2261e694022700c1a5deb82c4a2cbef7585
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:b04a80cfa1c0b485eeaf8b6c8f1f8828cf9c2387e013e5efe04da1edcf701f8a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:0445126d566f708af503fd1ccfea61d69a48651cea4f8fa23030278a855675e5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:65ded6462a39b021eb3bb22a133a1199b5c6d01e40044b87263bcd2169743e25
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:a563474b0c9b5baaddb9e282c6374f89e35cd9b8fbebbd8b2382257022cd338d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:31c7fb8a06d9d19d3402f5444d6cee15c2964531874277a8e18b6cc3857c297d