Sign inSign up
Tomcat

dhi.io/tomcat

Tomcat 9.x JDK 21.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

9-jdk21-alpine3.23-dev, 9.0-jdk21-alpine3.23-dev, 9.0.122-jdk21-alpine3.23-dev

Index digest:

sha256:35189a66f0ba6cc4acfd63347fe1bbe1b8ea8ec0d7099259945b97d7ae701627

Manifest digest:

sha256:0970f4d2c19e6c6623de09bf829fad79f50f3ee13a442c9c097959440af3ef25

Size

196.33 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tomcat:9-jdk21-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tomcat:9-jdk21-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tomcat@sha256:f62d4bf144e4261a01a549321fad1362a32ccc981275f906e8dd442a18b2729a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tomcat@sha256:d2de7ccda322b43715a7ac6964c4995e1ac2c8b74910b703ab08f019e90ce0fc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tomcat@sha256:708a05f1ce703a0f356b87e7548598aea1194e4bfabb4fefa72e706573c1b892
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tomcat@sha256:dc2f615000e66ea794809da638c694cfa76b40d84c9b497b75530179ff78c4be
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tomcat@sha256:7eee952c4b590f3b2242f6c9691a17248672731d81a5419dc889b84e57bae912
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tomcat@sha256:c206c5539fa457583ccbffe0f810407cf9f8e1e744397bf69971efedb1ef27e3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tomcat@sha256:d26297a36f463e11b749cbfa5385566320eee1e88ba6e316901a87e3844cfa6c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tomcat@sha256:ee9f85b8ee53298ac3262cb103f60a8fe777d972c24fd2b3fa848bb1e9eed08c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tomcat@sha256:dcb9a5cb2603ba324c7007597658f68bc1fd3a53b305719ed95180309f632d87
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tomcat@sha256:8c89d8db873a90843a74313bd116a1a516d191ef5f7d650fcc58bfe896abfd58
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tomcat@sha256:0e93a75813c610a8675e6b0d07704982fdd7412fb08eafb180e1a9f7cbeaed18
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tomcat@sha256:f72a0c049d9bfaccecb5ce45771bb16064bb5c8a5f53397142578dbb7ab96e7a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tomcat@sha256:0a2ae5c2573aad52b535b12259bc9c14083839dd9d5c5a09b7a2cf17f08207de
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tomcat@sha256:4c20a38cc987af300a25b4d15c6b9eef334d731ea35b80e13991528e1be0d8a3