Sign inSign up
Tomcat

dhi.io/tomcat

Tomcat 10.x JDK 17.x (dev)

CIS
linux/amd64
debian 13
Tags:

10-jdk17-debian-dev, 10-jdk17-debian13-dev, 10-jdk17-dev, 10.1-jdk17-debian-dev, 10.1-jdk17-debian13-dev, 10.1-jdk17-dev, 10.1.60-jdk17-debian-dev, 10.1.60-jdk17-debian13-dev, 10.1.60-jdk17-dev

Index digest:

sha256:4544fa377c921912d39617ae48efb55ec99b4c248675591ffc21023534b54b40

Manifest digest:

sha256:95e27756ab398c2bbccfe0bd9ffb667ba936e1fdeaa16b2a7863d1dd03636233

Size

159.08 MB

Last pushed

4 hours ago

Vulnerabilities

0
1
0
13
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tomcat:10-jdk17-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tomcat:10-jdk17-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tomcat@sha256:e2e6690d0a594988be3be435729431b219e86560d37959b0c45d72a3b3ab37e3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tomcat@sha256:1f8b0857df9431b341c44ac32790848b6d809bfad945c0fd07932215234935c7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tomcat@sha256:2b5c52fe298a163b829b86e31e46024e32e7118cb7dc88587b38506f0d328750
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tomcat@sha256:21ad0680cdf105bcee055253955b85c61ac699b19badb50abb30cead13f97c7e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tomcat@sha256:e79337ff33252708b1be370a24e4868d6d01f8d7edc6a00d5107d266d2381b23
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tomcat@sha256:ff5c1fbe78941c47563dbd8fe144d9399c923bffe2b0a1a6da02152bf15eea13
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tomcat@sha256:93c7422a2070fa28af166513db7d99185a3f8853bda83ebc7397d274705f1b1d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tomcat@sha256:783d30062d6905840de2b756444043a6fa1dce6346431d054e6208fc53ed4045
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tomcat@sha256:4c719e2810ba9016df14eb196ec72618c7655f393fe4b350ed469777e9149a5a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tomcat@sha256:493ac37b2c5f7f8af61b33f7cdd20f01c0a2ace76fdbe549938dbd0117ae1050
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tomcat@sha256:6842c476a058863d4762d001cae6dc4e90c5eed1f86710a333a52407b6c128c4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tomcat@sha256:adae48c3b6ccd585ed06c932fb3d7d88e15f15c84df709eead76053aa4d54f65
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tomcat@sha256:f17e8460c97cfed522d1f2cbc69ff8c774db438a7862499ed7653c2848a4c9ee
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tomcat@sha256:92dda4bde8030c39e46afb2b1fbe33ca764662a5c94ca31b659d569c385539dc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tomcat@sha256:c1fe2f8b7e0ab614a116e36f22c60b7aa03cf0ebdbf33d21d9da38e60352b3b9