dhi.io/tomcat
10-jdk25-debian-dev, 10-jdk25-debian13-dev, 10-jdk25-dev, 10.1-jdk25-debian-dev, 10.1-jdk25-debian13-dev, 10.1-jdk25-dev, 10.1.60-jdk25-debian-dev, 10.1.60-jdk25-debian13-dev, 10.1.60-jdk25-dev
sha256:fb8e658e82493957d82b411b4b45c0d48d1bbc0d47ca112dd1318a0b4be20a40
Manifest digest:sha256:ab2f27b4280dc30eb4d9fb1463fce5c63a72038f1cc54d29d39ff6ba4be05c80
Size
106.77 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tomcat:10-jdk25-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tomcat:10-jdk25-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tomcat@sha256:d03a297714f944200fc13457ca59da843d072b2ed49b8b0c1586f06d60041f1d |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tomcat@sha256:757c44d1bf8b6efb3ea807abd30755d56d2ff883ca887297a123f860bf215c3d |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tomcat@sha256:588b414678a204c84dc60bbccebbd103f71e087a2983c92a11e6cac08c18023e |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tomcat@sha256:d73b4186368b7f9098445f533f03df097972137eab7621f528c4f11c64951adb |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/tomcat@sha256:c11fda8898e5d7d2f4f38af8fdceff249585f895a17f0517fc7acea13d5c2337 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tomcat@sha256:921aa5d0e5fe0be08469d4877d0c658f0449963cf045dedb6256641d3b983fbd |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tomcat@sha256:149b669def8079ed9c28970567f6df378d568e825eef881faf49e87fcad600bf |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tomcat@sha256:846052b2f53cb5565173cf607fca71c88f3319f5ad87b288ba9034f05e228cf8 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tomcat@sha256:9163bcee0261af8af93bd8ca768bc0c8d176dfadf50068e112932a738fee14d9 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tomcat@sha256:e7e44d73eb6b2d55219de400ee4ede0c82d18940e5289f1c0acfa9f9a0a58ad1 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tomcat@sha256:985b4e3e2f6f9e8b20c1dfb3538b9ae772100da7e4969e5fb8b67aead2fd4d33 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tomcat@sha256:bf8520797583526fcc62377a6fc5a360268adcbc6013fb59ca11dcd3c2ca68fa |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tomcat@sha256:231409cd70c78993ee921abeeaed4c0677074bd8918e26a516bb6203873e4bd1 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tomcat@sha256:ac6b66f4ca0e8652fb330f160f25975c94af246f3dcb37c7c56c86f21927f481 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tomcat@sha256:0ea1561665764032166782ff2cdd1c5b3d1ac1f14ddd24e6ba568dc6bc1a51f0 |