Sign inSign up
Tomcat

dhi.io/tomcat

Tomcat 11.x JDK 25.x (dev)

CIS
linux/amd64
debian 13
Tags:

11-jdk25-debian-dev, 11-jdk25-debian13-dev, 11-jdk25-dev, 11.0-jdk25-debian-dev, 11.0-jdk25-debian13-dev, 11.0-jdk25-dev, 11.0.26-jdk25-debian-dev, 11.0.26-jdk25-debian13-dev, 11.0.26-jdk25-dev

Index digest:

sha256:ffabde4ad8b1290ee22010a20f72b4fb1b798a3ee6aa4d0a49b27acba8ba4ea6

Manifest digest:

sha256:a6f80033636d527401b3e92a5cbd1b342f3faf2aebf2cd91aa990ac850083c96

Size

106.85 MB

Last pushed

1 day ago

Vulnerabilities

0
1
0
7
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tomcat:11-jdk25-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tomcat:11-jdk25-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tomcat@sha256:2c3d6493e4f0cb994750155159b77033deffcc7441aac9db84395892f4e97d07
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tomcat@sha256:1c524e4357f47b2fcf10ab9573f2773d96bc8e4ca9d5a35d4a254ac03843d3a8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tomcat@sha256:101dc1a69da5dd05e09dd45cf0fd2ce90221130f16199f481b4bc80fd35d44ad
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tomcat@sha256:e64ae6a0516b85729b1d2a49916fb6202d02d24331db4546687af1facb4c11bf
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tomcat@sha256:dd2e743e6da9222880dce62307900795e431e80c3cea6397e5e88ab8b28011f1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tomcat@sha256:e7171e7aac46645374d59f0d86e36f5c5f5b7e06f21ac7b8ae73ce5f723f8f19
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tomcat@sha256:23e0c9bc75c3a04f95a54e3ccf66cbb6b330f133fd002672781ab5609215744d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tomcat@sha256:bcba24001c7cd01ef7536f28dd9467e906b3d46e5e281012f2e90c741a4c43cf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tomcat@sha256:e19fd8c9e8b8681dc811a3f029dcc02b6752358c661e951af2c2cb2d917ac680
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tomcat@sha256:d32009a407a9adf58fb3c505eba9b7634b7ca2d088dd61e3feba92b13fe05855
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tomcat@sha256:4dd2a01cb5f46c56abc4cf02acfb74a458ab641e226a9e0b133978c3f4fcc8b3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tomcat@sha256:2ed33f1253ca28d3709081aa7902762e226824d476dcee69348699b8ad816530
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tomcat@sha256:de940c90447e056d21067ac13b949c1900c415c3ce0f51c083a77461a06f6240
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tomcat@sha256:b66b211992e031867e06f3d8353c07297dd1c47c833c7dd74367bb6760055748
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tomcat@sha256:9a7d9571a275f23a5d537f2e02fa75c027b01686d00467379f619c998448e623