Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 21.x

CIS
linux/amd64
alpine 3.24
Tags:

21-alpine, 21-alpine3.24, 21.0-alpine, 21.0-alpine3.24, 21.0.12-alpine, 21.0.12-alpine3.24, 21.0.12.12.1-r0-alpine, 21.0.12.12.1-r0-alpine3.24

Index digest:

sha256:1489e89588ec7bbebe2082887594f2758b1eaf3698c90b73c03ce352c4bfbcf2

Manifest digest:

sha256:6c5a0ab6cc628be67366034206cae816e4c107a02eeacb4edac97425275dac24

Size

182.58 MB

Last pushed

9 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:21-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:21-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:65a1677a881c1356db7fd1042598427ce61fc73620160bf44833140a0ec05b72
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:519342186d33d0b082460a88399bc30ca1f8ed9a8f74e17d196900cb7074801d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:6533d36f13817e4be134e69816e3002aacb8dc3c6cacaf00f6691c31449f1b0f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:a159a08b916907a8799eb0fe495b91f32c40e4f150e29ecf567f1eee67e2f98d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:9c32044b159349c07951c15d326a578c60daf8696109e01fc66fa4d0a58f8e8d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:a13d20bf974bad9fd30cbc0f5159c4d5e66b04390a98fa2a1c079d918f0d2136
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:c6bca6df74ef5a3948729e4d41ee5372d2271ec4a780f349ea9d8d6c8dfb52f2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:2d694e05e0ea7090491629f5b5c852f9de56753b5a887b80cc9f91182c74807e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:c682fee53f7bbab5723f75bcf387c2b728222183a37916e514d5aaff2ab8ca21
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:54dd8493f92ca305ba6916c556c532ff924bbf42011836fb86a9c45b90af9c5d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:a3279831bb1c658aed8057c8fb8b1c00a09c3688ce9fc5350aa2f179618592b9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:c6609b38415e63315454044b179213aac13aa2835c2d1e35a6732d036cd4dc7b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:2eb4b6d8fabdc70791b0e3114f8592d8ae05e3fb289fcea804407ae9dd93ba16
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:e42e6f5a4fdc85949e5c39ff8b3ae460bbe172f624a626be6f1c4940075739cc