Sign inSign up
Tomcat

dhi.io/tomcat

Tomcat 10.x JDK 21.x (dev)

CIS
linux/amd64
debian 13
Tags:

10-jdk21-debian-dev, 10-jdk21-debian13-dev, 10-jdk21-dev, 10.1-jdk21-debian-dev, 10.1-jdk21-debian13-dev, 10.1-jdk21-dev, 10.1.60-jdk21-debian-dev, 10.1.60-jdk21-debian13-dev, 10.1.60-jdk21-dev

Index digest:

sha256:51ebfc96a9f2664d65404ab52e0694fcc69730c1668c98ac8b993694adbe5f17

Manifest digest:

sha256:fc1110378476dabd5bf40fd1b4ffd4567111b78be6190592848d1b6e19d15a49

Size

168.30 MB

Last pushed

7 hours ago

Vulnerabilities

0
1
0
13
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tomcat:10-jdk21-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tomcat:10-jdk21-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tomcat@sha256:3e323ffbe176d418513559a5be86b086d4f76475e191a8c28a03df8d0c611a31
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tomcat@sha256:a0278f6a9dd03dad9b6ae4cc23b60a71487189aef4f6ecf059a0610b6fb16156
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tomcat@sha256:5781b6fd9c2952fa9d6f662cb64fddbf86755a3e1a96dc8917d63282b5310250
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tomcat@sha256:d75f51aa4e2614b50d142ad4a7ccf6481c7218958e650f47bb3ed16282d7e001
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tomcat@sha256:85255745b231fc277eeab84145e87da77c4da058bc720496fc2ff709f95ed758
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tomcat@sha256:418f19797868323bc23912381bc55562d8c69507de944be6b4c39f628f7879af
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tomcat@sha256:e92a48967a41a65364cf594fcd1b03d0fcd578ab8409f66845977530064788f1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tomcat@sha256:77899aedd1d7378b8fbbf725f582cc6d23e147e985c4b0bf202d935bc07b1d5e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tomcat@sha256:8fd5d54d62c9895246694497f92f141ad8a451be476a1544b650e5c8094b1a04
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tomcat@sha256:ada6e8b27be64e8eb01c199bac1c408cf831233de1fe887c91c0b07c262e0a05
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tomcat@sha256:99c1fbe1a2011fe2ef2c0527c2d15039f3faf3b00ab96312e8967f0f52402220
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tomcat@sha256:c3d983f96addf80896581b24aabf97c0920030a03bbc3d7f6b9cf7489f84a0ba
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tomcat@sha256:07a58591e7abb47d977d42fd79cdedc97aea729e9e5cdf86fe32a97534afd4ef
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tomcat@sha256:102eb20c347e121994c0c70ecc38b408a55637bbfd647cbbc5a16526d5fd814d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tomcat@sha256:cae3eb650eaa48326abfa046c9373594c9ee964d8fe968060eb27a0999d54750