dhi.io/tomcat
10-jdk17-debian-dev, 10-jdk17-debian13-dev, 10-jdk17-dev, 10.1-jdk17-debian-dev, 10.1-jdk17-debian13-dev, 10.1-jdk17-dev, 10.1.59-jdk17-debian-dev, 10.1.59-jdk17-debian13-dev, 10.1.59-jdk17-dev
sha256:6191c98ab95f19cec31b4e59fabe2428447bdafe8e5483edba3ff2307d324ec8
Manifest digest:sha256:399dc7a057f8aaf6aec251a7d5b189bff8f1fa20f6d36531814ac92b99f0f459
Size
159.09 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tomcat:10-jdk17-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tomcat:10-jdk17-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tomcat@sha256:6c051296e4e720fd7b8614e53fee393ed4065cd95eaabb2d8a03722323498ffc |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tomcat@sha256:59dc287554276727d8bc8b888a7e4780a0c0f305d61f3e2527a528495b83ec5d |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tomcat@sha256:d1d0a74b9cf4e77cf50093d81ab57d18343ef59c9a361eb96c54c6f47a69322f |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tomcat@sha256:c0cbbe8a09978cc9dd589d53c2ae8cc0ac14aebdec2208c1a886b3d1bed98964 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/tomcat@sha256:03d3fe6a07d380911dc75261baab0fb1d28516f62a247e1bd4c27129e5b3cc97 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tomcat@sha256:58f32d198406731b55bccd7d67fa2542e7f8e09678ff98e189cda0943ccbd8aa |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tomcat@sha256:0f1fb43e779dc9fc0fd78f0b04d88536f071809f765c7df2bee5a4297db09f86 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tomcat@sha256:aed7d2a9080ae7b8e2307a47a09b658ce2c2f50521f36e5b2691e8a13f6b8a90 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tomcat@sha256:5502890ba96f753a034122d63d1244daafdfd5ef00e605c76afd7cef7425e518 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tomcat@sha256:15fee8b839512cf5446c566ddf4ddd53e312834bb5dd155f6d8e55ec61cd297f |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tomcat@sha256:9c45c16a05513227edbfc7bbbee541a158acd00ba5e12ad4a2c0b78cd9674dd0 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tomcat@sha256:4dfedecba641769b71b6c8e95bb825d33d59abf896e731597f31ae65b6abd48c |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tomcat@sha256:b662e79799c4e52bfb854102db7e720b2e25191d328bb5927e79fb4e52f825f4 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tomcat@sha256:2fb0f62435607bc3921dd51f171d2df932d02d4103e37703d356b48cb1ba75b6 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tomcat@sha256:5a9051f740ecfc444d639f610f4e3d4ec3cceefd4adc63409fe37fc0874b9817 |