dhi.io/tomcat
11-jdk25-debian-dev, 11-jdk25-debian13-dev, 11-jdk25-dev, 11.0-jdk25-debian-dev, 11.0-jdk25-debian13-dev, 11.0-jdk25-dev, 11.0.26-jdk25-debian-dev, 11.0.26-jdk25-debian13-dev, 11.0.26-jdk25-dev
sha256:ffabde4ad8b1290ee22010a20f72b4fb1b798a3ee6aa4d0a49b27acba8ba4ea6
Manifest digest:sha256:a6f80033636d527401b3e92a5cbd1b342f3faf2aebf2cd91aa990ac850083c96
Size
106.85 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tomcat:11-jdk25-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tomcat:11-jdk25-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tomcat@sha256:2c3d6493e4f0cb994750155159b77033deffcc7441aac9db84395892f4e97d07 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tomcat@sha256:1c524e4357f47b2fcf10ab9573f2773d96bc8e4ca9d5a35d4a254ac03843d3a8 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tomcat@sha256:101dc1a69da5dd05e09dd45cf0fd2ce90221130f16199f481b4bc80fd35d44ad |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tomcat@sha256:44d3c05d50bebe8e74332696d3076a00efe3790182edd092907926419ad35a3e |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/tomcat@sha256:c0de9cb9ca8f27de863a41f9dd695d34c5745c9f9d1c4ee80a42ce626677b8ec |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tomcat@sha256:e7171e7aac46645374d59f0d86e36f5c5f5b7e06f21ac7b8ae73ce5f723f8f19 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tomcat@sha256:23e0c9bc75c3a04f95a54e3ccf66cbb6b330f133fd002672781ab5609215744d |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tomcat@sha256:bcba24001c7cd01ef7536f28dd9467e906b3d46e5e281012f2e90c741a4c43cf |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tomcat@sha256:e19fd8c9e8b8681dc811a3f029dcc02b6752358c661e951af2c2cb2d917ac680 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tomcat@sha256:d32009a407a9adf58fb3c505eba9b7634b7ca2d088dd61e3feba92b13fe05855 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tomcat@sha256:76b6ee25314874ce73908180f9c2f7a58271b804b4dc6ea8e825dd1c144cf832 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tomcat@sha256:b5cc8ca6d11102750addd05a19a98874ed5086d7712e7a47c8c93ee74edb2c1f |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tomcat@sha256:de940c90447e056d21067ac13b949c1900c415c3ce0f51c083a77461a06f6240 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tomcat@sha256:b66b211992e031867e06f3d8353c07297dd1c47c833c7dd74367bb6760055748 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tomcat@sha256:4585b80eaae199d2a3b7207b9b1543748c6119dd20d16465267073f05b9234f4 |