dhi.io/tomcat
11-jdk17-debian-dev, 11-jdk17-debian13-dev, 11-jdk17-dev, 11.0-jdk17-debian-dev, 11.0-jdk17-debian13-dev, 11.0-jdk17-dev, 11.0.26-jdk17-debian-dev, 11.0.26-jdk17-debian13-dev, 11.0.26-jdk17-dev
sha256:19ff9f4dd84348b08697147451b63b694aad51e960b0fa446bfee22509114a38
Manifest digest:sha256:2df760561c6eba3abd6b49eea52420a770445aeb053f407cded58e5eebba864f
Size
159.16 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tomcat:11-jdk17-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tomcat:11-jdk17-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tomcat@sha256:96f2f73294e41a762c79510e80a43722bf793539291d91746f2ceff0d191bfbc |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tomcat@sha256:f446bbc35ac5a2e3ad9b0b1b8c5bfb6baebf4b39ba2cf6626d5924e892a2b79c |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tomcat@sha256:4e3af6b378b2d86e93e0564e45b5a8faa142a41ee504531d04fd0cc04b36657b |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tomcat@sha256:b082946b23ea8069af8fadecc2b971199a455be7b9a5199736670d9136745c25 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/tomcat@sha256:7fd5495cd2b54b38583f146f3104bceae0212bc4e50924799492e27ef1ed449e |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tomcat@sha256:201b96adf9795e623175f8ee5acc04817cfa6d5fe0a438c3ad8fdbc3a85268f9 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tomcat@sha256:439e19107049a80e03e0485304f7d02454fc9f388e0ac5ab980b8792c232618e |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tomcat@sha256:3a2acf7a10eb35f750a91471a0caed152623e1a1f6028c2058029b94e4ce17db |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tomcat@sha256:6bf4b9767857f38add5bab821a655e6d0ca5e798165191997b8238e1d89d423b |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tomcat@sha256:45f03761eb3411b76b936e5561b73df0aec3db754d71ecdd0a2c53bcdcdf027b |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tomcat@sha256:ec4691789fcc050187b07b84eb42d0b0746e90889a9cfca4a425eaa3fae03c2a |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tomcat@sha256:2d0658aa42196fc7191547483b0f1622a5b34a235c466bd936cf967eed1f303f |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tomcat@sha256:f939717e6dbac5613d03e67c410402a748f10be209e3d181a5e6a7d71aaaf700 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tomcat@sha256:caebc2fd6270109fd6a7707fbd25925c1259085cac598fb7ba838147fbb5cda3 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tomcat@sha256:b2e03797f7b7a3b42a28c423bb505e34209269902f78f3c00ddc736f9a8b982f |