Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 25.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

25-alpine-dev, 25-alpine3.24-dev, 25.0-alpine-dev, 25.0-alpine3.24-dev, 25.0.4-alpine-dev, 25.0.4-alpine3.24-dev, 25.0.4.10.1-r0-alpine-dev, 25.0.4.10.1-r0-alpine3.24-dev

Index digest:

sha256:561f28ecaf6a4bc8fe0babba85d8085665712ace811a7275f8e8bfcff73de0ab

Manifest digest:

sha256:e5b2a0f1a3be0d7f23f6903395ea149ed90819ea1cc4a79c494eddd09d47a132

Size

203.66 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2032

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:25-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:25-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:64f206613167b972d9729cef0f1a351d875d4cc48e9fe5b37defa91e75f6532d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:c9a9db4206373db2a5401546833e15b84143e765c8d49592fb8e263bf6f52715
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:5d6be5a4ad8380a5e23176ea42df90d82395b7ff2bffcc717f285e393f60a236
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:0cabdc97532e48ab7dcf1066d51f194a778d5223a87f7ea721f63e9946ebdc98
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:52cb9356eaf3e79705caeae43bc634f04aa0ea3ed6049cd8fa17321e3ddcef5c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:77c57fb0744d9de7b563b34105960b42fd82f73e5d66d30726cb59cf904fb95c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:26438bbc08128d0595802a9bb4af092b09c7008f615abff65216b77c72410333
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:51fc57a7698d3f7ca4910fd49451fbfb0772a808063fe0402f15a1a200d3368a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:78e689b40cc10f68ea06f86c5c1474f88fc3c1abc22b5007f53535f73a6d925a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:bee34d6340e883cfe09d5e8b797ce935f45c60147b538e12c4e48bc3607f565c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:8028df33702e3e15a0631a0543f92cec43a5ad8ffd9b0014b887cb24d8dee1e3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:586a7a092570653a90ea9cb37eddff15bb86d6cd62a4e1597be5b4c2ec786394
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:b2e5acbc909a1b1025193020c6ab5658174026611fbf7b7af47721d908c7174c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:653bf2a5d5b81176e76074a18e7715c5cb0319ea6efff30ea50938807d92b6e0