dhi.io/tomcat
11-jdk25-debian-dev, 11-jdk25-debian13-dev, 11-jdk25-dev, 11.0-jdk25-debian-dev, 11.0-jdk25-debian13-dev, 11.0-jdk25-dev, 11.0.26-jdk25-debian-dev, 11.0.26-jdk25-debian13-dev, 11.0.26-jdk25-dev
sha256:f95115afe6c015622b5a3af9994fe253350f3ed049ff2a2079b39720630ff5b6
Manifest digest:sha256:4551b2de3a107cbc8f9c3a46b4e4ad9ce4d31122ed6cea3c7f24806205b6ecb6
Size
106.85 MB
Last pushed
1 hour ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tomcat:11-jdk25-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tomcat:11-jdk25-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tomcat@sha256:548b606d8112b07406417a625a988e8bc131592af8d6d1f9a772cfc66d6718b6 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tomcat@sha256:b0b1291d33177a3f380f013061f39e018d5670d2e19ab78ea7b30665bd54493e |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tomcat@sha256:ce0c71277b9e49134b646f56f22acfe53ebf4e523e92ad47f4800b832d4c3b1c |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tomcat@sha256:22303a537c93e88353afae7390c452bda0662b5d75189bc161c84082166a326b |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/tomcat@sha256:1e8f79e15a12638aa1fb58ace3a7a57bdd11c6f2da188208c75e30c6c42b5e35 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tomcat@sha256:73b9c932f3abed53c86c6be954b7e138392c8046c7c70596b2106a35e174a4c1 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tomcat@sha256:4b6b5145cd8e8c9140b123d20ac733f8a3a810000dec07315cdf5d18a75542f1 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tomcat@sha256:1bef10b13a5d4ab2a56ac019ddb03e8403465a0cee61b2c2eee90b284201006e |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tomcat@sha256:ff15ec4536345b68b1b95c8024eb6d49fea830fac58ef65bd693f1f888ed80be |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tomcat@sha256:642b0e63966f842eba09b3448bfce3162bdb22dfa122c755faee481e338e2e50 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tomcat@sha256:abdb7f99929f343ebad8286a7c92ff96e86ac2a86d810a7754ec5b4c86d46dbd |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tomcat@sha256:3e344cac56a224633b3c55b98b667f4ea896955eeddd9eef527336609d9d9842 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tomcat@sha256:821f5fe7c3d3672fcea50b438bebff702f6c8ba2b6ae57021adb83658ac5441c |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tomcat@sha256:d384528c7837df883f3065cfa92c63596e480d02fb39be4af024d0ca4f13e9fe |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tomcat@sha256:602209c18f37ab55e47b6536a416876c8adefcbf2d93d2244245fc6b7a7576c9 |