Sign inSign up
Amazon Corretto

dhi.io/amazoncorretto

Amazon Corretto 21.x (dev)

CIS
linux/amd64
debian 13
Tags:

21-debian-dev, 21-debian13-dev, 21-dev, 21.0-debian-dev, 21.0-debian13-dev, 21.0-dev, 21.0.12-debian-dev, 21.0.12-debian13-dev, 21.0.12-dev, 21.0.12.12.1-debian-dev, 21.0.12.12.1-debian13-dev, 21.0.12.12.1-dev

Index digest:

sha256:da3c1bf6a0ec0457d472f5500163415258881e702b3e7f9173b0d0a04da933d3

Manifest digest:

sha256:365cca8572ea465b8bd4c541b308617fdf069607e6eca51c4e8b8758a809c212

Size

209.26 MB

Last pushed

20 hours ago

Vulnerabilities

0
2
0
1
0

Support

Active until Oct 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazoncorretto:21-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazoncorretto:21-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazoncorretto@sha256:1d29183fab180eec5ae3b7369a18529847177ea447c60146c9a35553d15e9dfc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazoncorretto@sha256:2bf0b45115e8fe0adbcfd30e566363037be742075ebf0bc4a84d1dffbbd81295
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazoncorretto@sha256:858365bcf59531555ae08a271e33807a7b533ea7ccd2a649e22afff0dda4e92e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazoncorretto@sha256:cbc6171e541c74cd2f7a6a564cf2196d646678557779eaa8484aca3f84808c87
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/amazoncorretto@sha256:0e91047bf0bbec258eb2b2d1f02444373128dbbd6d9a52ec442b26a05c37547b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazoncorretto@sha256:c8c838733c77061ff1a2bcdf1a708242b1831e0c38f9ef91b211e3cf2c67e9a2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazoncorretto@sha256:c2744ca2f0017d41560ddc7b0977f920f0740a1ffc5f7e2ca2178007152fdb00
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazoncorretto@sha256:291956725188afa766f5637fcfcc4e287038dcae81174450aeadb56a14533575
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazoncorretto@sha256:a5402adb4d4b59d54babb4889bbb15df3aa777e594e66dec4ac2936ee767fdb5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazoncorretto@sha256:f324a5215067d1dbee9455103168d500714ece66da8321caf9f07b0028c00c45
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazoncorretto@sha256:e5678cda1b1a527d2fd607340981b62960fec8b92a479373ce8be41030815b3d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazoncorretto@sha256:c07ad4a771d534424998f6e70b37e509ccad89adb389a82cc18c7f0b5bbb19b2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazoncorretto@sha256:3f54bbc508b40ee52e080c6b0c46530e7bc482b24748786712756e7993aea87c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazoncorretto@sha256:8b8efbe7f6f405a84f82f041687247cc90f1a01428b1f809232b14529a0ec699
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazoncorretto@sha256:0f3fe13a9a9329d9a99e830235720b928e00c4da06f26996bd2bb3acc0bd8c75