Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 21.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

21-alpine-dev, 21-alpine3.24-dev, 21.0-alpine-dev, 21.0-alpine3.24-dev, 21.0.12-alpine-dev, 21.0.12-alpine3.24-dev, 21.0.12.12.1-r0-alpine-dev, 21.0.12.12.1-r0-alpine3.24-dev

Index digest:

sha256:de2c3a2780cafea12357b940d138b8d58850566b113d3a80b36c9b3c41d32f1f

Manifest digest:

sha256:a7b64d1a3eaccc2c12d2637a3f0b4866b524c134f611fddc86aa5f2777396fad

Size

185.55 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:21-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:21-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:1478380afa74aca28e36d2f5fbef3783f3e4e5b8313ba502b7187bffbd4ffdb8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:4806877c200bc6413211182f6094d28ba6dfc353cd97906375f0e20f8d2e6e27
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:950227a547fef19eca1884856b4b882c805cc575fd77ab2cdcb5784c2f7616d6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:874b12a986b3628a04f9b589e4d096abfb63132deffca320a051b0477179ca15
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:b49b076c7a4cc206d8a64fa9e8dcfa97eda69c17fc9c720f8c648ee2aeedc626
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:29fe3ec47c5f5a40677c206fe102fbda0d19f52fe5ed4fd5f86cb92b9c0d15d0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:d9b7f51f677c0ec1e77d8150cd8dcb80d618519d6e408a6542654d3979f0a164
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:3bd4f7b6e6a80a9d52ecc239c163e8f12f794463468e8fe4aa7c8e9633b2b74a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:3f1af9752ac9837454c8b0c7bc64d9fcf9dc0cbae64c166d36b72567d94b7089
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:bf0e7af1a7600bfa0f10cb983b70a5159caecf0ca5b0976adf8b7b0730e8cb3a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:0fa449e32dd5421bb937671e835d1d9b31d5a08e7247f25d3baf56b5167224a2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:f9ecca0da3866804ec82cbb773d076bd80b57f86e6b17122db20714ad410b977
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:208a7b12f351db33097660f565ec4bc9501cf9c5d2d1168ef2e0a9872dee590a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:b732402ddd821a290afe080cbea201f8ca87d2cf6f79166903dfc0fee7dcc079