dhi.io/tomcat
10-jdk25-debian-dev, 10-jdk25-debian13-dev, 10-jdk25-dev, 10.1-jdk25-debian-dev, 10.1-jdk25-debian13-dev, 10.1-jdk25-dev, 10.1.59-jdk25-debian-dev, 10.1.59-jdk25-debian13-dev, 10.1.59-jdk25-dev
sha256:c9ab606e8bbee97a2566d05efa8c4a6518ac1ed479e744524f75b9d807f1b0e4
Manifest digest:sha256:9cddfa25c4b729a14a120f1e276359eabf43036c56bec5897e751283c7803027
Size
106.78 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tomcat:10-jdk25-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tomcat:10-jdk25-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tomcat@sha256:1111e72eb64e1907ba5a2733a589acf923fcb3d3ff3278b361a87dea2ead8e31 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tomcat@sha256:3c685636775e17dfaa57f03a2f47e5d409f13c338ac27675c440f3a60f012d77 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tomcat@sha256:6b27844887d41c6e98f70d476e68e60485de6f6f646164dfc92050b5cb314221 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tomcat@sha256:b3b98db7821410ce6971845f08e09df5afd8f5c3e6a3eb26dbfed7bb16d30da0 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/tomcat@sha256:428b92bf14b5626d40bf3dcee0c230350358cd0612ebde80cacdc34c70c092bc |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tomcat@sha256:ba4380dff6ed3dfc9b3f767e42302f5f1c470b5b679b525946658f7e815d9655 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tomcat@sha256:9bafd1a331a74184791b52f58aa6bbceb44aae045e77ee3c71850055566f05a1 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tomcat@sha256:8608f8077c16f62f57ff843999711c68b4c30b0e656c984d50331ceb40075c7e |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tomcat@sha256:ca926266ec923a7b488d07a752e5f6fd819caa29eb24bbc5c0342f2cc342ee7d |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tomcat@sha256:0ffddb111a3e44bc20aed70c17a7b37eb45e72f55f44c14ad4328c128ee04dd6 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tomcat@sha256:8ffe5404d25acdccb76600cc128ea3aaeec058fdda005b72a7df13045b7b6f2e |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tomcat@sha256:e7122cf7584e08a309c5eec3ba4baaa596331599ab08bb1a7409165176d1b5f7 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tomcat@sha256:e38cea03ca4366d58e727f9e34101ecc071fa2a5d299b159e1d75c90f4852604 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tomcat@sha256:d21319936bccd638f5a03b96a4bc58908fad20168ab2f7396eb4ee7ce8c5099d |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tomcat@sha256:2acfd6d3ffc1e966d6f07c7b1468b563488a468cd6bfec1e8540b67d571f85e0 |