Sign inSign up
Tomcat

dhi.io/tomcat

Tomcat 10.x JDK 25.x (dev)

CIS
linux/amd64
debian 13
Tags:

10-jdk25-debian-dev, 10-jdk25-debian13-dev, 10-jdk25-dev, 10.1-jdk25-debian-dev, 10.1-jdk25-debian13-dev, 10.1-jdk25-dev, 10.1.60-jdk25-debian-dev, 10.1.60-jdk25-debian13-dev, 10.1.60-jdk25-dev

Index digest:

sha256:fb8e658e82493957d82b411b4b45c0d48d1bbc0d47ca112dd1318a0b4be20a40

Manifest digest:

sha256:ab2f27b4280dc30eb4d9fb1463fce5c63a72038f1cc54d29d39ff6ba4be05c80

Size

106.77 MB

Last pushed

4 hours ago

Vulnerabilities

0
2
0
13
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tomcat:10-jdk25-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tomcat:10-jdk25-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tomcat@sha256:d03a297714f944200fc13457ca59da843d072b2ed49b8b0c1586f06d60041f1d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tomcat@sha256:757c44d1bf8b6efb3ea807abd30755d56d2ff883ca887297a123f860bf215c3d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tomcat@sha256:588b414678a204c84dc60bbccebbd103f71e087a2983c92a11e6cac08c18023e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tomcat@sha256:d73b4186368b7f9098445f533f03df097972137eab7621f528c4f11c64951adb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tomcat@sha256:c11fda8898e5d7d2f4f38af8fdceff249585f895a17f0517fc7acea13d5c2337
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tomcat@sha256:921aa5d0e5fe0be08469d4877d0c658f0449963cf045dedb6256641d3b983fbd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tomcat@sha256:149b669def8079ed9c28970567f6df378d568e825eef881faf49e87fcad600bf
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tomcat@sha256:846052b2f53cb5565173cf607fca71c88f3319f5ad87b288ba9034f05e228cf8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tomcat@sha256:9163bcee0261af8af93bd8ca768bc0c8d176dfadf50068e112932a738fee14d9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tomcat@sha256:e7e44d73eb6b2d55219de400ee4ede0c82d18940e5289f1c0acfa9f9a0a58ad1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tomcat@sha256:985b4e3e2f6f9e8b20c1dfb3538b9ae772100da7e4969e5fb8b67aead2fd4d33
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tomcat@sha256:bf8520797583526fcc62377a6fc5a360268adcbc6013fb59ca11dcd3c2ca68fa
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tomcat@sha256:231409cd70c78993ee921abeeaed4c0677074bd8918e26a516bb6203873e4bd1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tomcat@sha256:ac6b66f4ca0e8652fb330f160f25975c94af246f3dcb37c7c56c86f21927f481
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tomcat@sha256:0ea1561665764032166782ff2cdd1c5b3d1ac1f14ddd24e6ba568dc6bc1a51f0