dhi.io/tomcat
10-jdk21-debian-dev, 10-jdk21-debian13-dev, 10-jdk21-dev, 10.1-jdk21-debian-dev, 10.1-jdk21-debian13-dev, 10.1-jdk21-dev, 10.1.59-jdk21-debian-dev, 10.1.59-jdk21-debian13-dev, 10.1.59-jdk21-dev
sha256:c5538228a73c4fa53b2d8b1b10f2c74336643eed7aefe3c612da1a4515ad0328
Manifest digest:sha256:8dc93154a655753871db407d0fa7a802a532015a8a658045de49a798a9992c47
Size
168.31 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tomcat:10-jdk21-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tomcat:10-jdk21-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tomcat@sha256:a64713babd80b195169049a4d3623850df834bea71951b88cbc4127d34371f2e |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tomcat@sha256:661a7fc60fed8b6d85d2a0f30af6e3980acd1899ad362f89aed04cc86137147c |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tomcat@sha256:465a467f4cb003c391364765da7ea59e8f87f5aa434cc9ac2451d0b6b1b69325 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tomcat@sha256:884478efdb1f3531a1b2cb5b1fa2931c2a9da5c6612eec58e6c0dbc15d326fcc |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/tomcat@sha256:43b7f8a47f90472b5267815dd339853e2a5ec2a2885278a49c1c798fd59e9fe1 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tomcat@sha256:e076c9b9c31ae08c9e71a009bee7a6c3132ea24e91ea570a0838406ae8bf8725 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tomcat@sha256:b6d4b8eead13b82fc87bbe204a050d06f4ed6594bed1f0dbd06d301f7499baef |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tomcat@sha256:4bc551f2cc9cd9b454e50facc2c3ffba8b4c7cd0676292e0863682dabdebd64d |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tomcat@sha256:ea3e184edb286c0a8baa37ecafcb6f683aa6714fdca5e6544e0440ccf7b4ab3f |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tomcat@sha256:1f0bb0cbeb479a96b9e09ffe7fb1382d004786223f4d3c13cde7baad6ff0d9cd |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tomcat@sha256:f328bcac507bd8e406c3154e868eb9b23985c2032248d03a2c0eff4f6a8c8067 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tomcat@sha256:61e902670540eaa64b119cc217440fb3657cb632dbf0b923a9914a900933b7ae |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tomcat@sha256:b1224ff8f8b9c4034847f9c88a5871578ac609becffeb85d6f305284b2683e74 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tomcat@sha256:e8fcc6ed465c54e933961a186ff394f2055857a237e26eafb4d824077b75bbdf |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tomcat@sha256:e9d96c7eab4eb96480513d82200cbb90d4cbed802749a1c243795e1ab48ccf63 |