Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 17.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

17-alpine-dev, 17-alpine3.24-dev, 17.0-alpine-dev, 17.0-alpine3.24-dev, 17.0.20-alpine-dev, 17.0.20-alpine3.24-dev, 17.0.20.12.1-r0-alpine-dev, 17.0.20.12.1-r0-alpine3.24-dev

Index digest:

sha256:62ac4443b60b4df848702f29a5ac1138d200c453ec25162616632a2209254ba5

Manifest digest:

sha256:ea91a1df8fa5c6a60a63db139e09dd84ceec8558f17c907823af52870baa85a3

Size

173.75 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:17-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:17-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:9b33cc820f6b81d5b1830c3d07b7f6387a2aaed68702204fe0f9bd71e504aefe
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:0bf08c184193e2d03d8469b2ceeb91c63d420730959af7cac2ffccbcb08006be
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:b3ebff0b75e76e698a9ff5faa0331564b95eb76369946eff49c0194d21bd4774
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:fdd2995451e991f00657517ba9750f1d54a160289d84bfec2f1d84564d533eb5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:782b086d57b7650f0e385faa8748227a3d8eae3da7f629590de1e9e833ad9042
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:93cb7783b039ca758fd4bd0c217af4af6017323e3a48402f750dda8a1687f42d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:7098a6c2b20d548c5915d38d05d3b7f29601bc4b1dd02e665cf840a77358c2a9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:beccb21cad8390c42fce40b306979d753d043187be85b0d72f4c23bf677443b3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:caf24306536c8193535736ee9dfbb7be633f8c737e4a69193fc3e7768704acc4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:78da15f3575ec9190f55f8eb396b237ad0de4eab7edc027aa491dbfae0810a72
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:d5d872327de6f7788c13638a5083a191ec75dce3c4313be6af31895f28c72dcf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:04e7d2ec4cdab16fa79a18aa81149ead7db95e2554221db5f4825f72a69a2690
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:51d2f64baac9e8dabb7c2a0206a33bda402879e6c9ef1d4e9ecc06789ac0e567
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:20d1505073abb47cc0ddadfcc53f345cc46769d52a6cdacd2d73d8ff1fa4ac61