dhi.io/tomcat
10-jdk21-alpine3.23-dev, 10.1-jdk21-alpine3.23-dev, 10.1.60-jdk21-alpine3.23-dev
sha256:90a16267836f9d59e4a7e3f1a7b4714da76b3a3243d6cc135eaed754825e9484
Manifest digest:sha256:08382d93993dbb4b869e5b747e46aad0f575ad4d81fc58939ad9188040b5be57
Size
197.09 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tomcat:10-jdk21-alpine3.23-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tomcat:10-jdk21-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tomcat@sha256:e3abb113a86623a052456fd7642977ba0ed95b2ec053c270e1d266f035053616 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tomcat@sha256:86a38ab3bcba9d5ef074ab0094b95f850af11fb8ea58f1d8db47c8d56f4bc36c |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tomcat@sha256:9df9c5788ba8f5cca96da40b8cb277e81935893b4bbaae281b81b4a79a4e6776 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tomcat@sha256:c80eb50e0531bf87a086e402b6a32326e75a80e11dc697b2bc4df00b4df81ea1 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tomcat@sha256:cee1f13bfa5c25685c400f624f8004a64093d4150793cc19d540d326b53db991 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tomcat@sha256:406e197d846740f1d65fea7b06ff6054482d21600782df3bfd4a3c3281c77a2a |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tomcat@sha256:a548ec2680047be9e4db58514d11e3cb39428b64700030894909bd2a22bf5259 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tomcat@sha256:d3a9aa8e6c089d7cc20c558567da25d319161da5d125c3100e2f8201c2602557 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tomcat@sha256:fa1169c968ad371a10d9377f8ee6e5c24be6aa6050f5545041546f7d11ff4b16 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tomcat@sha256:2b13a65d36ed0723168d1a95250d215161872e588b81aaa77bd8113d20a0e4e8 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tomcat@sha256:428d5bb84d70ae5cf40995d2a1cb2ce1738a2cac0e28cd3c8b17851ddf6b927a |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tomcat@sha256:b833418dcbb8836650c7ab27086f65be1b5303970bd37863fdb62023da9c20ea |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tomcat@sha256:dea4874fcf16334eb1986dc45873ec95fa401cee13de638f206ae8b6dcf92ad9 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tomcat@sha256:ad1f87893ab9a20cfe648395e2c0fbe55c4255176d9242f6a2b76944d3afd987 |