dhi.io/azul
11-jdk-zulu, 11-jdk-zulu-debian, 11-jdk-zulu-debian13
sha256:a3c727d278b1b5d4bd359850e5f319a47325a93040f832d968ad37f0872cb707
Manifest digest:sha256:3227018b753b7d93e4a263aff450d07378d9d17d5af1eb4a461833243646e107
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/azul:11-jdk-zulu2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/azul:11-jdk-zulu --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/azul@sha256:18f22498e941b46ca514fdffcbc71fe9ee8ba84cc8163b78a4a9bc7d500b41af |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/azul@sha256:4776f2225d95b1567ad91d27483d08812ad6a943b45eb6de2a6d80d10334b12a |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/azul@sha256:362809a184c092efab2e12b1db6e88b5bdf08d639a8d260b762737677b8aad86 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/azul@sha256:d30b484793cc3984890d3382295c27ae95fad051c17c339bbe1f60e077ad275d |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/azul@sha256:80a490007b008795c31a1fe7620e2e6716c0338734d72c52b46337ce168725a7 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/azul@sha256:396db14107c21a197b718a65fe70757572a1f77c2b3d242a0cf722a2b716840a |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/azul@sha256:5fd90b7ed3113b1426ccda582e5169cfe03059af18d2e5fdaf1c52ddef11c20f |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/azul@sha256:b59c7f3963f5571abc7dedbed49b60de9a0b3948b35eb630f5c7100cd09466a4 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/azul@sha256:bb4dd522a55c99b8a274ec8f8c317d00c6c91bd58de4d79b0ff3e844f9e23e2c |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/azul@sha256:adde8c45515400df12e59018213de66713beb2b6e122cb1f0828d14bba9bf94a |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/azul@sha256:fb0342a067b3bb6e91817c08b526154cfd096ca3dadf50489810c7e4b80cd7a2 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/azul@sha256:850f00e18a28b012be431ea78fba27547952a67daa579b1a828d953f3d76139d |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/azul@sha256:3318c7b432f74bb6344478b0e604be2c7fd37250fff4f3fc52c27500e8bab111 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/azul@sha256:5832da2e337ec7beb3a7a390b6dce66d16b591ca008a007058b9199c6cd52272 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/azul@sha256:dce5265498dc0c6ce0abc16fb1101125f7e433cd8c24b02e2393127eb6fd4876 |