dhi.io/tomcat
9-jdk21-alpine3.23-dev, 9.0-jdk21-alpine3.23-dev, 9.0.122-jdk21-alpine3.23-dev
sha256:5fbc035b8e32e52ae4174ac4a66e6e8efa783ed6fa4533835b14c57398f382a3
Manifest digest:sha256:713e7c4c230a9118ded0ab4bfca35465120645ad9ef35e65b21ae0c709031450
Size
194.48 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tomcat:9-jdk21-alpine3.23-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tomcat:9-jdk21-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tomcat@sha256:39ee83b64969a643fdbdbde6b3a4764917fc7998c05c5c898e5e45a9aa83eeba |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tomcat@sha256:e76d239a5461d1d37e2ce7e766fed16202ade0f8170843372ca2ea90e96afaf6 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tomcat@sha256:0951dff6986520394d84907368961feb332b733e556275845f8b128757112106 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tomcat@sha256:4ca7e1a5e49ad15e6752185c5c98c0b0aa27512f6d7deb710cd5fe26a1115eb3 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tomcat@sha256:39a7e67461e487e0fb0719f55484d9470cccaa0ff297d5535d4a7fe351a62137 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tomcat@sha256:21764314ccf5b8bf3fd9a9db7cddd6611f54bcb1a74645301ae53ef99fb8d988 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tomcat@sha256:90f7d1637621b7cdb6ab5a732fea1ae805aa3785ff42c32e05678ed520f58b01 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tomcat@sha256:7e3223d4d47e6d39eb6ef3050fcd6c9a2cd28065ea05958450c082afdfbff8ab |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tomcat@sha256:d6ecb52986bec7f016512ffd0bd9c0b58f1c6d528a511663d0ef3497487e0165 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tomcat@sha256:261e02c7f967a2a3af7ef8a4a01062cc9f75d9127db6c22bb0be1ff1300033d4 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tomcat@sha256:6c84bd877981287dabd5a1aa8a8cac36531bc178d6ad3373ab326721aac5a4ee |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tomcat@sha256:8270c6b101d5fbae7e47fce3a88e3c71067d64a11faf3404e9aa576e1dbf4e65 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tomcat@sha256:e1e10e671efd4226dca49380c01703b78bdc9f60b4fbd21af4d17f18a3e48aa4 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tomcat@sha256:9d91d4a3021878a39699624994843b7b135fefa79fb5416c2f0739f2d49c094a |