dhi.io/tomcat
10-jdk17-debian-dev, 10-jdk17-debian13-dev, 10-jdk17-dev, 10.1-jdk17-debian-dev, 10.1-jdk17-debian13-dev, 10.1-jdk17-dev, 10.1.60-jdk17-debian-dev, 10.1.60-jdk17-debian13-dev, 10.1.60-jdk17-dev
sha256:74c22f06a82bd85da35eadce4f510f5e2036d82d66b415b0c84c2546606f162e
Manifest digest:sha256:7c0bd4d094c149eb0fa257c4f4bac8e7fcf61d6d4372b847631522884c86888f
Size
159.08 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tomcat:10-jdk17-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tomcat:10-jdk17-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tomcat@sha256:2f7c57735a0f66a0d58dd20dcd994fb866153b44855b396d494fe9aec4c972a2 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tomcat@sha256:63423ebd788c866a2df4dbe7c0e3a161047ba0395c80f2b54e307c610010fd5c |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tomcat@sha256:5435deac0f0dca4d319fc264be2be3d71471a0499864c8b02dc3457444d1255a |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tomcat@sha256:03b9c88961762377f9a82e760a671da3559e78256cea6131a675eda86281456f |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/tomcat@sha256:519960817390e137e2f522fe89c51fe71fcaf98c689fa61f79a644043f9b6944 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tomcat@sha256:a1637757a1a48042326383654c785d16a8730bdb52af296ad48cb9719672ec7c |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tomcat@sha256:ed310e82cc7ec9fdca8b22dbe9a38eb68e8d3dad0cfcefe2b9d4cfc10f529179 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tomcat@sha256:522bc2f6e1ea2f0999a072421e6791618db6440c68cf2187d05638e706ddef86 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tomcat@sha256:fc1d0331cb735f5c17d2baf1640e2b8d4fb98503d608373860892817cbca3196 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tomcat@sha256:0f881ff4b3c64b87d009834f04aadd6a661e8bab6658c288e9c0ef698b87143d |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tomcat@sha256:b68243634b2664c7b76966663fac1ddd6e4600d1b9d04538e066ad9e2cec59dc |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tomcat@sha256:035e4b45e91b48f3c8547b23acbdb6db3a1fcffe78dfc9ea8c123155309141b8 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tomcat@sha256:e7c63dcc350e7dc357286b2c6d712935411c223eca580944db1d7ca36dc41751 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tomcat@sha256:02df800b670605b8a4ce6b6f4312910c3e15ba4fa743e9199083734a49db4f8d |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tomcat@sha256:0d89d3d074e53e8452100e8d76a651b7c5606c0c75016480846664cc79bb7e62 |