Sign inSign up
Tomcat

dhi.io/tomcat

Tomcat 10.x JDK 17.x (dev)

CIS
linux/amd64
debian 13
Tags:

10-jdk17-debian-dev, 10-jdk17-debian13-dev, 10-jdk17-dev, 10.1-jdk17-debian-dev, 10.1-jdk17-debian13-dev, 10.1-jdk17-dev, 10.1.60-jdk17-debian-dev, 10.1.60-jdk17-debian13-dev, 10.1.60-jdk17-dev

Index digest:

sha256:74c22f06a82bd85da35eadce4f510f5e2036d82d66b415b0c84c2546606f162e

Manifest digest:

sha256:7c0bd4d094c149eb0fa257c4f4bac8e7fcf61d6d4372b847631522884c86888f

Size

159.08 MB

Last pushed

1 day ago

Vulnerabilities

0
3
0
14
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tomcat:10-jdk17-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tomcat:10-jdk17-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tomcat@sha256:2f7c57735a0f66a0d58dd20dcd994fb866153b44855b396d494fe9aec4c972a2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tomcat@sha256:63423ebd788c866a2df4dbe7c0e3a161047ba0395c80f2b54e307c610010fd5c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tomcat@sha256:5435deac0f0dca4d319fc264be2be3d71471a0499864c8b02dc3457444d1255a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tomcat@sha256:03b9c88961762377f9a82e760a671da3559e78256cea6131a675eda86281456f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tomcat@sha256:519960817390e137e2f522fe89c51fe71fcaf98c689fa61f79a644043f9b6944
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tomcat@sha256:a1637757a1a48042326383654c785d16a8730bdb52af296ad48cb9719672ec7c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tomcat@sha256:ed310e82cc7ec9fdca8b22dbe9a38eb68e8d3dad0cfcefe2b9d4cfc10f529179
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tomcat@sha256:522bc2f6e1ea2f0999a072421e6791618db6440c68cf2187d05638e706ddef86
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tomcat@sha256:fc1d0331cb735f5c17d2baf1640e2b8d4fb98503d608373860892817cbca3196
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tomcat@sha256:0f881ff4b3c64b87d009834f04aadd6a661e8bab6658c288e9c0ef698b87143d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tomcat@sha256:b68243634b2664c7b76966663fac1ddd6e4600d1b9d04538e066ad9e2cec59dc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tomcat@sha256:035e4b45e91b48f3c8547b23acbdb6db3a1fcffe78dfc9ea8c123155309141b8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tomcat@sha256:e7c63dcc350e7dc357286b2c6d712935411c223eca580944db1d7ca36dc41751
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tomcat@sha256:02df800b670605b8a4ce6b6f4312910c3e15ba4fa743e9199083734a49db4f8d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tomcat@sha256:0d89d3d074e53e8452100e8d76a651b7c5606c0c75016480846664cc79bb7e62