Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 8.x

CIS
linux/amd64
debian 13
Tags:

8, 8-debian, 8-debian13, 8.504, 8.504-debian, 8.504-debian13, 8.504.04, 8.504.04-debian, 8.504.04-debian13, 8.504.04.1, 8.504.04.1-debian, 8.504.04.1-debian13

Index digest:

sha256:e4585f3dc1cd80095ae62cca20eb621073acf8ac193f5e074280e498612eaa82

Manifest digest:

sha256:314ba0fdd5635c1378b8208fe09009a11163e0c408272fa99d0e8ad810b536e5

Size

97.99 MB

Last pushed

4 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:8

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:8 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:4b50a88333fc072a7f088c691f77a905e22077ec132a52645343ae0214b07542
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:a58277c9a8627214411c95cab2b8cbc63288408b1c83e616a1d7657db1c1846f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:5a97480f3c818d691ce6fe87720e4305498fa18bfc5cf3e3cb48d6a7a620df99
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:b67e2692167107a37f5eb1c5877ac4fd1d6d304383217261bc0db7af26bec89b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/amazoncorretto@sha256:0adf9283b3f28f1dc12f47fe4b15b544d2cb4892ff090da0cc399f998dddcdbc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:7c46b479032f88b693b0c92ae67db30c888811445a387ede2e6168f28d8c4e5f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:cfc9f22ae5005f6c0c3cc0af32fc689776cdf9648e40c8df6b242e9e7d55e012
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:7e73add01db9c0248d52cfbee2fe86ac398328eddd2feac04f640b7d12a6fc6f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:7fd6114bc71b218e099fe2851d2119dbe7bff00b855017ae3b21367ce3ee22c6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:378265da022f13d570d32b1f1d5ed6a9b3615d040140bc94402eb2c781a72036
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:62553b5e69681495329e419330536957ca4164b8cbac98156b24bccbe944e74b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:4a43d7f2ba5b5d1e5c57cc348ed351533e2e1cecb229033e8ae81076033ddc21
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:9a9c8b2a63def515e36f665a776d3e509728283fb6e249522bb81a8082481f8e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:2dcbaaa619843f08de4539d2ec14967115763c618a80a2a18461e1ba29d172a1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:21991526eada2a1ca8876afd6045510d0a4d5894e531d396b571e36a29d95b04