dhi.io/tomcat
9-jdk17-alpine, 9-jdk17-alpine3.24, 9.0-jdk17-alpine, 9.0-jdk17-alpine3.24, 9.0.122-jdk17-alpine, 9.0.122-jdk17-alpine3.24
sha256:7eb3531776870777b6800f3e351b02f47d8784ec5b1ad36f1870585f0e009cdb
Manifest digest:sha256:6fda3ded1dc61dea01ebcf82f3f3dd3a24bab50a52a55e9f7396fb3b3e0febf4
Size
50.79 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tomcat:9-jdk17-alpine2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tomcat:9-jdk17-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tomcat@sha256:e18e9e6d9e793c33f563383c34fcb8c86362fdfa6055f43586f71171be44ad3f |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tomcat@sha256:3dc2efac877872eac9930680291c57cd81bc254efc4a6c37dfb40a18fccafb8a |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tomcat@sha256:204d76878a9bd9f8a68c6ba4ca3ae9cb97fb0d5efc74ac1119ced4cd19da4d57 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tomcat@sha256:d83b2a724f6e7affcf8372b64a2591720cb758000f74eded913707fb0f05425c |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tomcat@sha256:951d5ee283df3a4112f8a016fb2772e09d122866657ff761652c56285e74337c |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tomcat@sha256:391b0bec57e0787b0599eebb2c729a8d97ee2704a389bbfc3d00eec286ea55ad |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tomcat@sha256:ce2ab539372bf6491f7e89c2e6a99beb27d98717f4905e4edacccc47a2fa64bd |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tomcat@sha256:0a83f8d4369be97bd0c0f812c1fa01722ba91cf4c4b00b52176fc45144d4337f |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tomcat@sha256:18d61db4dc9664380207d47ff50298b021905cfac22e91435c2eaefd3cb85e42 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tomcat@sha256:1fd4b0b9efc83c3a881cb8f6900968b9d3579c4221363da3a131a662c3640d39 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tomcat@sha256:e277ff7513f9619dd4ccc8c7ea52f23d8715131f651e82f7ae02a7eb0312ea1a |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tomcat@sha256:24e7eb331e06013b818b9cde2dd54e5cb047f89d6160d4db48f5ee726cb28945 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tomcat@sha256:75eba0cd20f6ff7b2763c59baa95b376768d86fad388f444c1be326257648e88 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tomcat@sha256:8793afa8f3561a8769335ea93bfce1f3b77b44543b670b8dc81d276524e954a4 |