Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 17.x

CIS
linux/amd64
alpine 3.24
Tags:

17-alpine, 17-alpine3.24, 17.0-alpine, 17.0-alpine3.24, 17.0.20-alpine, 17.0.20-alpine3.24, 17.0.20.12.1-r0-alpine, 17.0.20.12.1-r0-alpine3.24

Index digest:

sha256:a02fb62bb91c632133ce62fb1f3885b23df7e84228b6791b870146fd499bc64c

Manifest digest:

sha256:ae3eabba1284c1283ddc56bd93218ad08f917be4133100644ab180421483230e

Size

170.82 MB

Last pushed

9 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:17-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:17-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:ccf24e4223d4abb4914e36d3b726a9a97133164f060c7b4f7bae7750e928a959
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:e24a6ff6fa000aa367e39157d85fd5a0700c007c42fd794e77bee03158f4d619
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:a6b4e427e55147e34176df8dfa6d13d866a5d18bb211dd232b89e2a11e120c84
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:7089751ca1123e0691dd2bff5e53e5b88628324fa023f035fda31c07a64fecd9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:101d99900ae86c131d21db3c14fed7b0d08e848ad6c56167ffb5bfc56eae3491
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:1cd10ef0dbf823de295d4319656d4520c6031e203f6dd1c2e0faa95b0ea76525
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:a39d0dff0f915f1eb9062c5e6b2b403dae4970541a6eae6bf4e27d78586c6dfa
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:a631b456e9c396a341fa62148beb37691e34e21c6e8239a39245747fef6eaf88
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:d2d298184657b1c2258503ca9b0cb86f7517641958d570a4c583894593f98dc0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:99f7dee0583f70bed8fc1588e976a7c1af6532ad70f46dd1746fa3470297a0bf
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:0325a5ad388fc285d5936781581dcc3b2aceb4c24770ca97a2a10407ec8f8f55
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:e77aa8b904ecd0a994d4ea690b2b94a4f99632c33495989c5b9de0b180e84d46
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:0f01a4cf2b0f4d4aa203471041f51c5f8b0d5d86031ea2653e20a7a0c30de8da
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:2ccaf52f784c08614c64083c7346945306e6d7cb4a39a5f1c712bcb3bf29a10e