Sign inSign up
Tomcat

dhi.io/tomcat

Tomcat 10.x JDK 17.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

10-jdk17-alpine3.23-dev, 10.1-jdk17-alpine3.23-dev, 10.1.60-jdk17-alpine3.23-dev

Index digest:

sha256:9ca31cd7f5e0092cf43559c2fed4868cd371e7edb9972dd186c2cd3e0335adad

Manifest digest:

sha256:caa2fb6f5e580768bbf193ee45a034ad3bde616d0c380ba46f65ed9da7864605

Size

185.24 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tomcat:10-jdk17-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tomcat:10-jdk17-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tomcat@sha256:f65e121650d51110c6a7e853c9708d3e6a609383699c05e201624d4306d0546c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tomcat@sha256:35cbec548ba0180f7d4bbda1cf5de89cb781053008d0fd6f3ce703b0659b259f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tomcat@sha256:d04216de4cd25e0d8dcc3fee274454d8007e6c9cdf9be0f7149ccccbba94906b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tomcat@sha256:dfba2690c1e53430b9d36ed900d10a2a09808899c839126c2ea62dedad55b161
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tomcat@sha256:d2a4813416636a894fc1b2f20cb4ab1c82fbc9735332cb9338da3605f1d5655f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tomcat@sha256:3b3c985f08fdd707c4c3d678be41a9f12782242f4cf05a22104c681a29808a89
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tomcat@sha256:03c391286679020bfc1f8bf9fdf29b88a6aa04ea7c2c81c35b026447c6bdfedd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tomcat@sha256:edf782a07c0c47b64b67074349100dd4b8487bc88c2d335d2149a268f6703025
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tomcat@sha256:ac57221b139d4232d25e3ae08615aa79d58eb7cd9463c2b180a51a05028d457a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tomcat@sha256:09a73db0455dd2220c0c845171bbd421b0c5dcfa63ec99d90df398794320c07e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tomcat@sha256:d74763f05d6f649bcfcec92e61255aca05d32f80b89145d43c8a2b0e915b4cb1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tomcat@sha256:f51fe4d3583e2eb99eafed59ee94870c121b011eff8a7f9db999d434581a5cae
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tomcat@sha256:78dd8945e7b1d013abcf9192e93f350ad9f05c556351c3714db9016d0cc4f7e2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tomcat@sha256:bc80378a4bb0017995f64e301590369b91e7b75f9c26bf2e0f5140a3e576c26f