Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 25.x

CIS
linux/amd64
alpine 3.24
Tags:

25-alpine, 25-alpine3.24, 25.0-alpine, 25.0-alpine3.24, 25.0.4-alpine, 25.0.4-alpine3.24, 25.0.4.8.1-r0-alpine, 25.0.4.8.1-r0-alpine3.24

Index digest:

sha256:9ac23647c29be436c0f925762577c7e422871a1da6d0074027820562c29ff64a

Manifest digest:

sha256:63373de53b787655b51ab8ce47bd44a06a40e83a4522731567c1d508b3977958

Size

200.72 MB

Last pushed

15 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2032

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:25-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:25-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:301734aa412862efaf7c44bdb3ba1bbbd69e0722390c806912d834130a6e2f3c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:a30b957964263c8f4ed3c79a107f0d724a5dda4ba3de7285e78126783064a3f5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:0346f417c7fdd62b44c27a69d8ee1ffd2d3362ec4f5ffbb7b52921018167d676
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:2f5d82ef1e645bbbeb80824ac0f8c37f75ba412b5d99b0e0f887a4c4bd3d9789
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:3144d81a6454985b93d6297790f8e6b42d7d75ab559e82bea303a1a62b751c54
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:25b138a070c242d9334a604ac4b7b5316ad15fc0b9bff5fad45d0503438c34b3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:c2ab66f56e05b7e0cd8ae4afd1d7f4cae60a304aea9ce0ed46de12af562ad5f1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:4ca30ae65ed87063550b3adb4455767df0a10dc7cd5664678053b74a61bda79a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:8ed0e3b9ff42788a566a4993a769bb96caee354194d944ec27733811ffd27f32
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:5a54e7998ac0c852998d85f65e20020aa64f0755298c1c1eedb9bada88e124e6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:8ec356fb32568915cae54798027a1bc2c356ac89bd96d8761d5435f4efc47cbb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:fe02c372e1a4abed412dfb4c6a7ae55fd7fef3abcb62bf644223bc0cf86da335
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:d03aea0a20c2ce0a85bc20d4d8e4cd427b07cb69d2106f65de69023964ff8f2c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:73b833ef45d4ccc5c99023f8f64eecd5193814493a4106df023e471753ee9082