Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 8.x

CIS
linux/amd64
alpine 3.24
Tags:

8-alpine, 8-alpine3.24, 8.504-alpine, 8.504-alpine3.24, 8.504.04-alpine, 8.504.04-alpine3.24, 8.504.04.1-r0-alpine, 8.504.04.1-r0-alpine3.24

Index digest:

sha256:8f2440b8075d7c1d08c018564202cb3738ebc4e7d76f4a117eb00caa4799fc38

Manifest digest:

sha256:28086aed318ee4ce3142d3f7d17c2f7eae70f236a4891888a9a6d24387ef0b74

Size

87.15 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:8-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:8-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:12fe101df55f2324d6aa30c0d385ad88b1594a281e218d27462c11a61264b488
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:8f9543095ad6ef5436442e2793fafee07f0f4df2cee45a27bc65df4bdedcdfca
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:e9335bbc4f3ca852bc189183d1946315186dd6a06c2d8cf7f4af1b6a13d3e878
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:17962420a53513732494be3b5c9d49844c82a129debe7bcd819ec1b33c23c098
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:8a774ffc46fd7a0086bd624d20e768af38d8b63d47b3c2ca7db58245e3abc172
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:8fb36acf0ceb99e5fcca2dfba25b3bb319e40814177740ed2f7b6b3b916e45f2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:f0e883d74558fcabbebda6690f699290f1ca9a072a5a088e29eca3a799c3106e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:497a8c20b506954184a3ab302da16e496af287d508d2096c9c29edfbcf045dc8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:2f47d36a094e20194d085261d00de44a85428ab5d00833b639da179128db80db
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:73431bd8854b54c27fd66771bd413ef6a442ebf0311b27f922d5e82d47cd2c38
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:089297456431fb938ee07233a569530df3ca60e32f82039662009b7a7e7f82d7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:6eed6ed5f918c6eaa02bdff4705c40c0d447507d84bed220b4e72bad5724e797
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:7cd62b71bdb8d688836848598d939099f1270e77b119bfc801566835ee5810be
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:3f4dcc39e60127c6c0565e02946c2864375d24ae6635d8a19e160c2f19fb85c2