dhi.io/tomcat
11-jdk25, 11-jdk25-debian, 11-jdk25-debian13, 11.0-jdk25, 11.0-jdk25-debian, 11.0-jdk25-debian13, 11.0.26-jdk25, 11.0.26-jdk25-debian, 11.0.26-jdk25-debian13
sha256:096a55d71bafd83a3a725f2d3f1b052d36b201d40e4fc0b0c9afe534331e11af
Manifest digest:sha256:31797ac570f7843b0148c13bcfc0573356467140e2b431ba09a24309636f97e7
Size
70.54 MB
Last pushed
6 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tomcat:11-jdk252. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tomcat:11-jdk25 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tomcat@sha256:aa70d180ac5b6d72979967620dcc392787dc5ceedb1f9c1283cc10934f0c235e |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tomcat@sha256:73ff4985fb6f3ebd1038c8de129e0205c0c8f5af0e6807e3fd71f3c93ae41cd5 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tomcat@sha256:396bc441467d2cd3da6b49f326cbeb75e977a2c45516baa08d89374f360d36b4 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tomcat@sha256:ce4f60ad34ed63d0d00f9151cea7a9490599d4b794a31a19d6b8c00573a38f44 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/tomcat@sha256:49ad69638e70979acfe459df84a91f6fe26f806a5e5cde0761cd1d6c2fa610a0 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tomcat@sha256:d437ae2bea358f3d3d560b79799bb97087524bc14d995cfe07169173aaa23bde |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tomcat@sha256:19df7dbfc35511c6b0194a0e758c996ae71c6c1edac403562b682d02c681126b |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tomcat@sha256:abe9c18b56620371cc37a5c307943ac5eae0ca22a401581a8b6eb515804f328d |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tomcat@sha256:fc37dc995faa676652b2ea0bf2fd19f2161d67bf5c0767f164999443f6bae9d3 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tomcat@sha256:f9d526c30222d14fe36af1a2b8b5bd63167b432aea69567cc855c3bbf8b1ece9 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tomcat@sha256:a6d28734a163a85d4f13e6547310b76ed644ee5db996c6b7f8d4ee5d8143eb2e |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tomcat@sha256:ed613cd983a1a809669c2752020d5cb00564ba9948f0af0b72e971a21788f05f |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tomcat@sha256:5bc12ca172be76150dd05b0f6d97325a83a79076dda2b0c88f027c7653b2a2f4 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tomcat@sha256:bb81a4d8dc2fd77067661b5a3544af7fec3593170ea9aa5348af094812e793da |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tomcat@sha256:0316472f0cebda11c1a0eb32f559c4ca97d98d1ce2b196e4f4b0165642a9fb96 |