dhi.io/azul
11-jdk-zulu, 11-jdk-zulu-debian, 11-jdk-zulu-debian13
sha256:8ee52fbd6d552f364bc90bc300f2430fb6b783a63652cf10bd5e6a75dbd0f6ad
Manifest digest:sha256:04859f857eb4f0adb763e6cc71987ff2134c70101f03eb31c21358abd064932a
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/azul:11-jdk-zulu2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/azul:11-jdk-zulu --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/azul@sha256:10fd6e1af5d10224ba12ccee29b7168012d4350b18b0d56c887b1b00fdae42a1 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/azul@sha256:00049335305382dbb4c60268983a41a5f32fc6403c0fe220d1f6cee30e60cf2f |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/azul@sha256:1d8e0fdc1e067dcc1c3f168a145ba44c9f043c4aa6f222b35052a07d67a007e0 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/azul@sha256:e1e7a7fa5c08be480efa4ac8bc41fcdd0bc2c0d0346e464bf94b858e82f255f4 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/azul@sha256:e565132e4d7e1302b50a2ef458cd14e31ac962c4c67d30cf827390a003a0c3da |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/azul@sha256:b4637c21e629cf52005a4e59a5f580227b0fa6150d0d8f2858cf199079e4c7a1 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/azul@sha256:90c7620bbbdd66ae870d846ec715a9cf5d73b524944317a3bd9da7345a6559bb |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/azul@sha256:bca397c2fcb74e06ad05a28165957177132159eff443bed0556b346cf8751a1d |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/azul@sha256:0f5a36b7c439b86b910cfc5eb5d8113b145c5ce67e7200bd08c86f7644874e46 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/azul@sha256:72f2246832c5fca6ce2e06349fc241d1072d4d09e010608fb57e99db061e20f9 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/azul@sha256:3d5b7809098c225e1e6b6a81645efe54f40b7bd54d77db7b6b0e357dd68a4819 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/azul@sha256:027ea07b139c6bee5e5c801784a57d72abd04988d6d429978c8bfb37e0346fdd |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/azul@sha256:bf55f1772c0f143c41e1c8c1de6be826222324d404194f568883c5deb3d30096 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/azul@sha256:c1447282190c784ebe988bda7e0224529654f4c1f8396bbcfefaef29ed062725 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/azul@sha256:ecbd02b6131028a444d814b033bfde82c8cdef4b63252df42e6ee44f69b6b493 |