Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 8.x

CIS
linux/amd64
alpine 3.24
Tags:

8-alpine, 8-alpine3.24, 8.504-alpine, 8.504-alpine3.24, 8.504.04-alpine, 8.504.04-alpine3.24, 8.504.04.1-r0-alpine, 8.504.04.1-r0-alpine3.24

Index digest:

sha256:ba98adbdbcf7b10b642c5894f69a9bae76d0bec581bd4f7683dc1a7aa6302a91

Manifest digest:

sha256:2f65418fa429602cbcd2ead668eeb553a45dfabb6e0263c4657ab49f8306aef6

Size

87.15 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:8-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:8-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:90b377ee216f730092872f7cba9d3860d08d7bc47902dbb6755818ca2453ba81
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:c7b4eac9229cef833edf943f495e11018d682010dc4a865610ae2f96f33be461
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:1a20df0baa6118d202b7c30fff97b06a22b1d4296febbc1d880fe093408ecbe0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:8cc619a9d926aa2f9f64af22dae02b9b2b9c1afa9f632a2cedbb055d500d24a0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:c9a5c78d98dc4e777c6c2656c63e881f540665fc927986a0a47340099f9c7616
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:2082dd43c92b3087dc94f5695c27b0ff133c7e3b41434f9f0ae133be199bf3b5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:818c03235b39889f9e24ad33d4d6ac44b953a21d6ccc11d4d2bca44e1454c65b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:1d35089dea5bf97693c9dc8fddf7a4299f95aec5632bb89bafa4647a10977824
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:3542da04b878adc60ecfae9bad08256c71a80adfb1c26ed9d089a869cf45801e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:8859ce34d56632734139babcf5a681f385816f86e92bef2383bbed5664367994
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:b259a0ed9cb559ebef3bc728cd1a6518a09ce74e295ce056023c20078d3b20d6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:5c536d899c225fbbdf2d29d1c5561a6cdb52abcb1c7067cc2176c6cb5745cc1e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:45e639da57db9ec2bf8f6cc019ba1636322e2e206b7e0d17cad18e7d47951bab
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:eea35cc7638434a8aedb6d050387fdb430e1c661989339538ebd86c5b87dbff8