Sign inSign up
Tomcat

dhi.io/tomcat

Tomcat 10.x JDK 17.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

10-jdk17-alpine3.23-dev, 10.1-jdk17-alpine3.23-dev, 10.1.60-jdk17-alpine3.23-dev

Index digest:

sha256:14a2b1f0a2fc14cf065a199c6dade5f4bc1f13aae3caa2c5eadc21438f0f07e5

Manifest digest:

sha256:5f657d9c9e34efe55991fd4acca450760d92dc0acf7dde006431904ec407ceef

Size

185.23 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tomcat:10-jdk17-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tomcat:10-jdk17-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tomcat@sha256:51552c7b772a78b59b32facd91b66fcbad20165d6c66f0e16783419892d45c53
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tomcat@sha256:26b8b5c6afba6f57bd407ca37ef19baa287ccaf49ae21e331a6f7934e2f190ea
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tomcat@sha256:5f9f703167d2dbb3c690fa9dccd906a196cf339c0e56fdecb2092f76c2fac9de
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tomcat@sha256:2daeaae9836175cd4fb956e313ac3aa952671f11f556186e4e0b55f99a53fbe4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tomcat@sha256:26a8147df1ba145a5c4baadb23a37e7488933a3f972364a83dbdac4e029b7f90
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tomcat@sha256:e554f86ea2b735f7a28fb1dc3cdaff0215417de6f6150df4188202c73b7b67ad
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tomcat@sha256:32bbf4925b2e9ede0888109ce80e2193bd5447eccd88ea9f605814308d9b2312
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tomcat@sha256:ab9af447c2ddf19c7e34553f9346295a37a326b1e0f69e92e24da2b85a4d4a7a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tomcat@sha256:fe0347435bde8ed68d4017a21a7a9c820b20ea3c416d55fd44bf3a58734c5117
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tomcat@sha256:15efc52cd851911cf3e58a2757048221682cf7574a76bf6f542d1ee5130f6c73
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tomcat@sha256:ce0cc59795d2308d9fbc7d1c0b3f3e33b1de9a497772adc5ed3ed793242e0f39
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tomcat@sha256:302b4afe98ce619cbd492e2016707c31beafa9f232976e12b8a5c0f5a801368a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tomcat@sha256:b07771afbe58239fb6ce9403d0df368cd2ea6bdcce75800aebe9d6cb7699ce03
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tomcat@sha256:e4ef2cb5d1b8731e0fea8918348355334faaafd0f41f804125deea36043e2ac4