Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 11.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

11-alpine-dev, 11-alpine3.24-dev, 11.0-alpine-dev, 11.0-alpine3.24-dev, 11.0.32-alpine-dev, 11.0.32-alpine3.24-dev, 11.0.32.12.1-r0-alpine-dev, 11.0.32.12.1-r0-alpine3.24-dev

Index digest:

sha256:9ca07a4cf429611a2fec052e0bdc6072440de5f94bece27ed7c894c895a06728

Manifest digest:

sha256:31bc88ba003ebe172ef74eaa6f6a1c9d8213ce80e3995793e2b166b19c2e0078

Size

173.90 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jan 2032

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:11-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:11-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:00aac04c99dd6c7efb0c913cab6d757b44fff5e5c8c06f887e667fb447721227
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:b7de68f696296563432b672d9be00da8c851082a55d7b05a0b5f23c25b0309a2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:7b49431a32090dd60d1da6a1cae527daad85618a257a39388648e6e7fd1fd6ed
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:33e88cd42d9b46faae8d402f6bc455cb0c888aa292d23f15512ce85f1d7f01a5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:fa6cccebc78aa908883426af75b3a9cab3939ddd69f5c47b46b7ef3a815cb74b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:66d899faa48a8124c26595dbd9a45878535f0c86102ef7f6710a67ccffef632c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:0423484b628b2619f8c67d0a22cd97916821fcb8a16b3f16078a17c2882a0bc4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:21df4f5fdd6cec13cbc440af4b596920d2e95450b39338fd030bdf1766761d3e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:5785aa46f498571a8fc9d52a98ba7ad5854df422626170898cdc03fbcd3b0254
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:6e1810292c78239ebf588bc4aa9411adb52a25a6305ef39d6089e53fd539bc45
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:6f2796467543ee434b025f8ef3b6ad19b9e093080a64bfc01070cb1b14aef55b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:676c799a657f9a315d279519ae01b2e80bb38c065841f406ac605693373c2621
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:92ddc6ea27839ed8699a1effee71483f9fc5f98093004cf7cd2335726b9271e5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:b343e79b138b1bf1421044eb55b56145855728e8f70ba961541b0cf55406e56a