Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 25.x

CIS
linux/amd64
alpine 3.24
Tags:

25-alpine, 25-alpine3.24, 25.0-alpine, 25.0-alpine3.24, 25.0.4-alpine, 25.0.4-alpine3.24, 25.0.4.8.1-r0-alpine, 25.0.4.8.1-r0-alpine3.24

Index digest:

sha256:dacbfbcf2fc27db2b9e04c719c792033eceb08da1274245878903abea8ce3367

Manifest digest:

sha256:cf5aa9271cbc0b0d5d6e23f39ef69ea2fce2fa40c3e2cb2116cae6fa5d3db2ac

Size

200.72 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2032

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:25-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:25-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:5df405267f9fd2aa18970c9ce43eaea1bcdcfa5e63864dba5ca43c1c27d1648f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:1db407dffe90996f5b2b821d63749299afc7386e6bc81b6ed0b979e6a4bce3ac
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:6b5056c066a8a851d1f6a2c4618ca22f9ee1941605454220020d15c0374424ec
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:cbe64d7ffcf8bb27feb25ca437a730737311bde78dbc2776b1524f51035a5712
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:9e1e7e54daa769621e7ab3c53effc79ff2c3d3f16c60321e34aad338cb6a691f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:0a1199b20dea473034359d70b4028d73bf66b4dce0b0989637a661a54e6bc68f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:4dbab3b642b2f53bc547a79be45a339c2ed2e8d2dffcd2f03f716a234c576bcd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:1d919b96f43c4efa7442f7e4e839a8130910af76782ff600793a5ce4c6a6a5a3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:d23f84768e6c6b7ce5221d38e9ccdfc50e9a1a5dd545d25975f27fb840f1e4cb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:a947884906334dd62c70cf5c65de2a994e853a7f35a6f17a08066aefeacaf966
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:b1d7b8b70878374feff6faca024cd2459007891424f05529bd7885e81ac4a05f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:68f9898309d2d308b5876ed4d9cc88b66b100da17e37531ca80969a88fe9dfd4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:aea3d82da695b9843ffb812b99058ad2cc8fe5efdab72351d7ae408f8c7bdb26
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:3e13e653a6596e0193b33a456e9525c3194629a7759334ce8519860cd8fbabe5