Sign inSign up
Tomcat

dhi.io/tomcat

Tomcat 9.x JDK 21.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

9-jdk21-alpine3.23-dev, 9.0-jdk21-alpine3.23-dev, 9.0.122-jdk21-alpine3.23-dev

Index digest:

sha256:5fbc035b8e32e52ae4174ac4a66e6e8efa783ed6fa4533835b14c57398f382a3

Manifest digest:

sha256:8e3801236ccb248940b63cd6795aa9a82bb77b89a77bb83608ea68116d987462

Size

196.33 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tomcat:9-jdk21-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tomcat:9-jdk21-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tomcat@sha256:afcb76ff562ad634aca792c62f74a8dbe97a5f31ce03771f4e9b72bc8b757311
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tomcat@sha256:48238cb337fffb91b04782299527518c080c816710da9bd49ba59a22a4fdb4c9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tomcat@sha256:094f77dd862ad5831a2ddcf67e6b57da71a6c6be3c34510e6358b5606119ff8e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tomcat@sha256:656bd2f78aefbc099730bf7c3f8d3051b6ec4663cb95717daccba46dc8bad469
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tomcat@sha256:63bf7deb9c3f6106a5cd6c1f705ab77cdeceaefe5c320fe5ab8afc0e87fc11b6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tomcat@sha256:49e7b2bc42a306bc8179c7d7ece0332205ac7b228bdf41961e93504fc46b5fd9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tomcat@sha256:efe07abb3d135ddd95c2d2b127cc4e2f07920f15cce6c25bb228b4c85aac5082
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tomcat@sha256:7cc930420b021dec9c8c7672a8aa25b6cb9094be075a78271dc662db54b265c3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tomcat@sha256:7f1a9e4c0badbb1d6ba9573b4464c9d6882dc6c110e39ad04616bd68ba741134
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tomcat@sha256:67816dbaf8261d7bfaef1a2c01b58e411996f0e0f4390c3774b28d1765764318
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tomcat@sha256:10683973a44a9bc1dde41fe54fab33b3b84f46d0558ef5394387d03b4d05616f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tomcat@sha256:0a4d2c16612cf6e859acf3331463b1e9b7b6d2e7232b469031a0453fb3dcddca
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tomcat@sha256:53319c627f367dc3c3ac7bb2f2205cf251594e21bbb4967ebde74393736342b7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tomcat@sha256:f08bd4e163459d72d863ba6bb73e8259e8489983f3b7fd0ae46684ab1e6c534b