Sign inSign up
Tomcat

dhi.io/tomcat

Tomcat 11.x JDK 25.x

CIS
linux/amd64
debian 13
Tags:

11-jdk25, 11-jdk25-debian, 11-jdk25-debian13, 11.0-jdk25, 11.0-jdk25-debian, 11.0-jdk25-debian13, 11.0.26-jdk25, 11.0.26-jdk25-debian, 11.0.26-jdk25-debian13

Index digest:

sha256:e59184e18561d967475de11524f352c355c5c4a058e7b2c5a2ad3989dd2f6fd6

Manifest digest:

sha256:5f62d10ca1af04ace0ea20c58941b1cae897eea6fbcc279fabf3a89087ee7b9a

Size

70.54 MB

Last pushed

21 hours ago

Vulnerabilities

0
1
0
9
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tomcat:11-jdk25

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tomcat:11-jdk25 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tomcat@sha256:4e4a4bcafbb15819370117fbebcf51af767dc2e33942b446a635a9f901a9cce6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tomcat@sha256:e3a524b371f9beec0d4513e3611c6bc66e99095f8c9ded69899b15e809b16026
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tomcat@sha256:73faf0bb8c0b1f8a85a1f6da1a37df79bb70a0db0388560212572fb18a6e3d17
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tomcat@sha256:957d797feb5cc8497696becbaf045d84468a87b52b23575b45046d77c2b08d6b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tomcat@sha256:18b00fee576621ca4dbac25f963cce8b1d7d9c74d7f74e177de87d5dcef9a88a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tomcat@sha256:24a8e45b4d71f5e4580b841deddb412d5fda3e8c307d8ed8b758659b409ab8c5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tomcat@sha256:eaf4bc86ea0f69a239fb565b350cbb6f398ec7ee70cd1b58930a9dd6d6f97474
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tomcat@sha256:7335a7c97cf6960584d9289c05a8c8c848debe7501c4a3d8499558422afee74e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tomcat@sha256:f83e1c826c445ea769e49deaa13b7e4ece5908c3854ccb95537527f265edde45
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tomcat@sha256:e7e9c109864ce7c8e18f7b9095e52be4f7b251350239edcd37d0945cdda1f819
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tomcat@sha256:9b30a94621b3dae4a398d36c2468c8c8499d9e0fccf46721ade458fb2c803d97
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tomcat@sha256:499a905e4659e53838e26f224cf4f2e260df9cf24fdb489af294e4541e554436
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tomcat@sha256:588d2840d1245fdc7497328979a48511047b0727d60c354c183de191872445e4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tomcat@sha256:73ccac8809f20cbd6b967513cffd9945ee64ae38cb75c5f96de61b511f17c058
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tomcat@sha256:7c4ee0b21c6197e3aa0275424cc0408e889ce497a03a672bd291239969d9c3d0