Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 17.x (dev)

CIS
linux/amd64
debian 13
Tags:

17-debian-dev, 17-debian13-dev, 17-dev, 17.0-debian-dev, 17.0-debian13-dev, 17.0-dev, 17.0.20-debian-dev, 17.0.20-debian13-dev, 17.0.20-dev, 17.0.20.12.1-debian-dev, 17.0.20.12.1-debian13-dev, 17.0.20.12.1-dev

Index digest:

sha256:e08596183add61c75322f33df395b0ef890332d8c9592644638b1086139e85f5

Manifest digest:

sha256:0410f48a7064b0cae620bcc8ff2f8e67f2afe5f53e6208a4a7400300a70262c6

Size

197.60 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Oct 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:17-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:17-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:9060568603eea9148904ea930ac52e72badce4f2f2c47b71d57d01d25586e97b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:a2c9e450e8f22b9d1c981b1312f94510cb86909b72584c64c757fdc004e856cd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:3e03635571ff03c667879f68ddfce660e7174ff03ca0b8cc52461a51043fe0d4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:054eabb8af1df4b187e36074ef638ce7ef7eb54a09b0fb2644cf0edefe680cbc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/amazoncorretto@sha256:9ca2c38145f2ed30a85b056133c64040d972bf247b9b350a57c545a106b66819
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:a69d4c9007ea7c47d7018f96f5a33b82df0ede7e50670612064af78350081696
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:46a895db016f11cf68ece935637467fb650bc1cbc670e7abc1a2b1b9fbae05ee
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:131dccd11d765d546a9e1795f7406f1ce68c9888e3ea200afdad352722fa1fec
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:4a4e0479a4f0735845223be2807fb8a17d6ce69ae3e1533645728e7c69b45c47
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:ca3500e8a3faaa5c0f804bf151935830117be90e0af3b65cca3a748efc15e15a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:5a1f4c0d09b78bfde91ddac6f8cc0293af60864c91a50b06d503a136442e5bfc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:368e0d9a7998a6f5876d2b97305ffbf2bdd80bb4329fb7886bcc4f8ff4456a5f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:8cb99874bb850552c74daba9afd74a8c0e7664600a124c416eb8469034de06a2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:cffbc813169cbf39560779015aecbcf96418ac1209f2bfc71ccb1765c9f96e8e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:7a4e45689d7f2d4cd8873e73e1dc1ce63e30fea9f2d7111fc53d40833c7cb52f