dhi.io/tomcat
11-jdk25-debian-dev, 11-jdk25-debian13-dev, 11-jdk25-dev, 11.0-jdk25-debian-dev, 11.0-jdk25-debian13-dev, 11.0-jdk25-dev, 11.0.26-jdk25-debian-dev, 11.0.26-jdk25-debian13-dev, 11.0.26-jdk25-dev
sha256:ffabde4ad8b1290ee22010a20f72b4fb1b798a3ee6aa4d0a49b27acba8ba4ea6
Manifest digest:sha256:a6f80033636d527401b3e92a5cbd1b342f3faf2aebf2cd91aa990ac850083c96
Size
106.85 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tomcat:11-jdk25-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tomcat:11-jdk25-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tomcat@sha256:2c3d6493e4f0cb994750155159b77033deffcc7441aac9db84395892f4e97d07 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tomcat@sha256:1c524e4357f47b2fcf10ab9573f2773d96bc8e4ca9d5a35d4a254ac03843d3a8 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tomcat@sha256:101dc1a69da5dd05e09dd45cf0fd2ce90221130f16199f481b4bc80fd35d44ad |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tomcat@sha256:e64ae6a0516b85729b1d2a49916fb6202d02d24331db4546687af1facb4c11bf |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/tomcat@sha256:dd2e743e6da9222880dce62307900795e431e80c3cea6397e5e88ab8b28011f1 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tomcat@sha256:e7171e7aac46645374d59f0d86e36f5c5f5b7e06f21ac7b8ae73ce5f723f8f19 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tomcat@sha256:23e0c9bc75c3a04f95a54e3ccf66cbb6b330f133fd002672781ab5609215744d |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tomcat@sha256:bcba24001c7cd01ef7536f28dd9467e906b3d46e5e281012f2e90c741a4c43cf |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tomcat@sha256:e19fd8c9e8b8681dc811a3f029dcc02b6752358c661e951af2c2cb2d917ac680 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tomcat@sha256:d32009a407a9adf58fb3c505eba9b7634b7ca2d088dd61e3feba92b13fe05855 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tomcat@sha256:4dd2a01cb5f46c56abc4cf02acfb74a458ab641e226a9e0b133978c3f4fcc8b3 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tomcat@sha256:2ed33f1253ca28d3709081aa7902762e226824d476dcee69348699b8ad816530 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tomcat@sha256:de940c90447e056d21067ac13b949c1900c415c3ce0f51c083a77461a06f6240 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tomcat@sha256:b66b211992e031867e06f3d8353c07297dd1c47c833c7dd74367bb6760055748 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tomcat@sha256:9a7d9571a275f23a5d537f2e02fa75c027b01686d00467379f619c998448e623 |