Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 11.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

11-alpine-dev, 11-alpine3.24-dev, 11.0-alpine-dev, 11.0-alpine3.24-dev, 11.0.32-alpine-dev, 11.0.32-alpine3.24-dev, 11.0.32.12.1-r0-alpine-dev, 11.0.32.12.1-r0-alpine3.24-dev

Index digest:

sha256:cea21ecb8761c7a32509055cb6a6fc393e96af964001188d6833713b816167d1

Manifest digest:

sha256:bff6c002bdbfb6c7ef36a19a2839867fa3bca2ea6adcbd60deda1af6b004c207

Size

173.90 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jan 2032

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:11-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:11-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:5ac28ed521b029bdd1b70b7a6b9d8a4e3de928f3c49736a103c87ddd930201ab
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:c7a6998a2fb9e90db1ba438d1e6f631b4a15c0d32d21cfb840fdc2c0a8432d40
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:37e8a79008190652caf48356e8e7d3cccc2d586c6a775c66602f761f1ea8c9dd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:e8929218a3a747874060e16cee2c81fd0b6abef37f9485973276d65cef3d68b4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:37afec91b5b51a7a14e08293d3f8c4f85857564d0351c1012239c21b41039dfc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:20902b5565e63f70fbcbf76a6b393592c6e841fdfaf49282fd3b8e24ad79acab
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:5c3afa904e567292a89db72c9d060e06ef72a39fecd8b3d60f6a9a126dca529b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:9990dd73fc4aa8ab21a46c6dc9c962c02e28c26c25abcce324e264d1fe0275e7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:a958a887b6b37ce55ac1556358c2580b1c03c7df62592a6bb2adbb320c665870
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:1f7d7a8273f32f2e77a8930da2496933cf13e6c0f0859805d8736bc19050b725
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:bce2320a1730f8c5a75e638fd8d260c56c6ea271b3626e7f902441f50a88c10d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:257e7b0988737fcbc98d5f515ab531e777cbdaa55f783c084500027f945efd1f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:f1e68a09f2ee6700cbd278c5ea75c5b3f5aef258a1647e536581ad1bf9fd3a63
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:bcc719c7b6fc3d11e6643d03120841e0d36496f8c33be2cb9fc34fb7c8cce834