Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 11.x (dev)

CIS
linux/amd64
debian 13
Tags:

11-debian-dev, 11-debian13-dev, 11-dev, 11.0-debian-dev, 11.0-debian13-dev, 11.0-dev, 11.0.32-debian-dev, 11.0.32-debian13-dev, 11.0.32-dev, 11.0.32.12.1-debian-dev, 11.0.32.12.1-debian13-dev, 11.0.32.12.1-dev

Index digest:

sha256:12b62e74f9517ad211cb86a823e1bef900aa12051acdb4c7920fb4ff81ecf3f7

Manifest digest:

sha256:e7a61a7012b2bf4db8a3de9c036d9b499abae62fcb1e31620bed0471aa5bc7d5

Size

198.32 MB

Last pushed

3 days ago

Vulnerabilities

0
1
2
10
1

Support

Active until Jan 2032

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:11-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:11-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:3fff189e5cb6f5c1fd1c99adbeaa78546540ef4a8e35b0d7778dd42783d4d461
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:a7992084e330c565a409cf8fe25df8a01be2df9e1fa25227fc1b7157e7f26294
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:8710ee9421facfd8bac7814861758fb6dd452e83bed65f30b4eeed36dc7b4096
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:b2a621fbc692d7bbf5ae62ac7ac19cfa5a82a1c71e1fb9b33dc17cbf4536425d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/amazoncorretto@sha256:474de993291b86c8f9959bd4899b1bc32493d7d5bb61d2498554f582b66c0971
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:7727b4e9436d91521ef65676a2131cca474fed8a23e9e91cee059b73460499ad
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:e5e696761673a4cb7aa02df4e8797a94fc80a2175705b3ac43f7afc8af1a582a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:361d3470e60ef064aef470ba48a74f1729a8fc52ebe9e30a87bd8ba521d53b48
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:bd20d6e18f337ab5fb883c8a3a51aa577b3aaddd6ae45c63f358fd2e672dd6c7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:fa58b49770cb38197024b2fe102b5be00cb5ea51c504b18759ceeb9d0f47273b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:bdbd686819dc125cb63450f05266fef68ad713a2a0edc872fae8ded00f185f46
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:481298407779609b5e64d4bb1958b72a36e3bbc5ab610bd76f051e949b2ee084
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:f007c63adb4a7a0ab166fa43a2f3eb0160c2c0ff31e6b3a2118f3903570cb0d6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:81ecdba3e5bb2512d3ac757516c62290d74959b78afb10c4737076b747ff6be2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:f488044d421a32630d947af897027d68302ba171ac05d018413fb0c47efabcbc