Sign inSign up
Tomcat

dhi.io/tomcat

Tomcat 10.x JDK 21.x (dev)

CIS
linux/amd64
debian 13
Tags:

10-jdk21-debian-dev, 10-jdk21-debian13-dev, 10-jdk21-dev, 10.1-jdk21-debian-dev, 10.1-jdk21-debian13-dev, 10.1-jdk21-dev, 10.1.60-jdk21-debian-dev, 10.1.60-jdk21-debian13-dev, 10.1.60-jdk21-dev

Index digest:

sha256:58fdcc4b8eebb08857b3eb346af6fa8e9cbf10fe3370b30bb86db0aaf0c145cd

Manifest digest:

sha256:7b564362744747d446448dc57fc432f78c957d3c58618ba8534eb95e19841aec

Size

168.30 MB

Last pushed

8 hours ago

Vulnerabilities

0
1
0
13
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tomcat:10-jdk21-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tomcat:10-jdk21-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tomcat@sha256:d7b0a6d2582aadd146d7455673fc859c545eca859cf6f58a2f5dc6e144551b39
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tomcat@sha256:8b0a4293b5d07e165b9cecd94b07820e59e483ab7726576d7d4a303429abe7b7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tomcat@sha256:32ee3e954a9a4c64c20d1c13ce39e788a5ca28c69469c09aaf73e7c72f69ada8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tomcat@sha256:1e269b2e906a7ea840f5f54caa625f8b1e12aa4e9699eb013e0adeffa2e3479c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tomcat@sha256:bca3f64be80d9159c63f746a24f1c3049b79d2a5fbaf74f89c1795c8ac5f16e5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tomcat@sha256:ce46415ee341e9a08588cac0543533d77213e0ee6b86dcd58c1319ae29df826c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tomcat@sha256:ed28b7ecac72917299d323840a039adec2e18dfead27024de5af62ee02cf6677
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tomcat@sha256:73de2e9142ee7787cbc66be084899db78a8ffb75ca8facf8e3b33af644194bd1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tomcat@sha256:959eebbe0c99201dc661a57cc331961df470e4aaf65bf908c9034b9972d4aa49
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tomcat@sha256:a6abbc2d4c658d065ca64262ad803868b9b044ee0892f02b876efdea76ac68ba
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tomcat@sha256:e94f9971574a14083781230a93c9261c1a99c7f1c3af5475b41facf02868bb45
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tomcat@sha256:a4c47b5f8f3a6019198bd1b164c40c90dd946ff640f14555e44494f6d1535c99
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tomcat@sha256:f878fb3496390d8309798b0293664ec6424d2322972d659d8a640d10f302a46a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tomcat@sha256:467ec4650b6acc948c01d1e4eca96cffbea14579354335250abce3d579318810
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tomcat@sha256:ecbb39d6777bbde4a4b608c4780d43a2e3b4b2db348aed1489379e49ce38b156