Sign inSign up
Tomcat

dhi.io/tomcat

Tomcat 10.x JDK 21.x (dev)

CIS
linux/amd64
debian 13
Tags:

10-jdk21-debian-dev, 10-jdk21-debian13-dev, 10-jdk21-dev, 10.1-jdk21-debian-dev, 10.1-jdk21-debian13-dev, 10.1-jdk21-dev, 10.1.60-jdk21-debian-dev, 10.1.60-jdk21-debian13-dev, 10.1.60-jdk21-dev

Index digest:

sha256:0c880b894bef9e43acde56a52b19f39bd5df6d141e427eb4b83171e578de3aa6

Manifest digest:

sha256:4ac55b66f37c3b069e510a93a42f257e0f23860fa5180fadf5f04ef33a2e552c

Size

168.30 MB

Last pushed

13 hours ago

Vulnerabilities

0
1
0
7
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tomcat:10-jdk21-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tomcat:10-jdk21-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tomcat@sha256:9f3cebebf44c54636bb0097c1964f87ba1778669ffb702c51f61f8a919a3ba06
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tomcat@sha256:57ec1653c115c48c7a898f23aaaf3c316d4d791e4fca296c192888c703d89e36
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tomcat@sha256:ce6af890c5aaf24456d7a6ddacef198e867fef117569d2c4d037c4be8c28f7e8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tomcat@sha256:bf30dce7538c7e960121d5eaa30b70c471507b4e6016acaf569ced98036d2766
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tomcat@sha256:cc12e796a3ee70fd483205d8cc66e8acd6efc3a698d4ba645ed76ffbe5514a70
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tomcat@sha256:1e347a87c2ee8ffaf93fb5cc6ffb09f915d5931cec35ff11bcef223edb281547
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tomcat@sha256:b4cd8e17b74e0841eab19b5c117362970c2daf552a9713db9c3f370c1117a413
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tomcat@sha256:b9cbe200a540659a6b8e5f5e26649d962b9d2f7328b075460cc7deeaeda0be02
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tomcat@sha256:e68ee2220177a1864d902d0be07fbb21ad019b12cb0526b013c58cfc4e4acdb1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tomcat@sha256:bf0c3ce6f9cc380cb687571f653f7d3d1a8ede5e74c782b3c7440b8fe46882bb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tomcat@sha256:3a176129622274a3b9149663e7c8067541c2ad4622280ed171644e351d1e3c4a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tomcat@sha256:75a54ae979ba8e64dafdff4f81ea8dcde83bd5434973dfbf1c3dea0a80e097d1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tomcat@sha256:b2337addc1439f7d8e38c82006759c1cfed7674e122c4f8f533e3ed34611e6c5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tomcat@sha256:af82049e17ed2d0969dce572a9b7846ad794a47d9aa37533907f859b74b15573
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tomcat@sha256:5f28a97b5bc696b6dddfb828bd6bbd89aaabb69c4d5c3a4278b87dec75bea729