Sign inSign up
Tomcat

dhi.io/tomcat

Tomcat 10.x JDK 25.x (dev)

CIS
linux/amd64
debian 13
Tags:

10-jdk25-debian-dev, 10-jdk25-debian13-dev, 10-jdk25-dev, 10.1-jdk25-debian-dev, 10.1-jdk25-debian13-dev, 10.1-jdk25-dev, 10.1.60-jdk25-debian-dev, 10.1.60-jdk25-debian13-dev, 10.1.60-jdk25-dev

Index digest:

sha256:716bae97ac469bc0edb1d3df11be67d45b862520003d6e2604074fc2ec789dec

Manifest digest:

sha256:f5dfe3ed30dc32f31278ecd1b955963d9bd4d757b761015769a6d300138d4ded

Size

106.77 MB

Last pushed

8 hours ago

Vulnerabilities

0
1
0
13
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tomcat:10-jdk25-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tomcat:10-jdk25-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tomcat@sha256:68f580e13b40073178925fbd798cca5ac9f76ce01b942077c9d9b008f5156653
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tomcat@sha256:144923763e601185433a00f9f78b9ac7fcb970d87a14b1b97dd3d9666835c453
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tomcat@sha256:8a312b488d74d09f46088cb097cf4255807a21d7e56cb8962bae27e4ecadb41e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tomcat@sha256:3605189cf151c2bbdaa1e1275be24b1f4bc2ed180fa63dd7fecef68bae00712e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tomcat@sha256:f990cee31a1e401277e00bae45a6f9afcc1fa733de5efa99c0ba6b433d740fb8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tomcat@sha256:8a1df99e21ed846f540cdd97149e9c166c8724c3d87e4a2a009419db1fd99460
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tomcat@sha256:e6d15d6774b9e28853ed145b542cf88621c6b87d9f4889c433ff788efc3d45e5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tomcat@sha256:1fff615f2d341e5152b05105e74e3170df7ee5dbe44649076e58c870bcf262fb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tomcat@sha256:d5e68810ccf7a64f33a3d96b7403bccc5cbe0fc68d74c061838ac98c2c6bd459
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tomcat@sha256:fc78a5985488b0ec4b93532c32021066e58a6b386b367dfc9e97f46dc158801f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tomcat@sha256:03a75572aff845079377238ca255949363d916d4181814d8e3692500ddf6d9ba
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tomcat@sha256:b68a5b1ebdbefeeb13b0b2674cbe7cd41bc0c0f4abd211afb9f54f538247d87c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tomcat@sha256:279942b5f91ed3da9ac6a4eb6417fb11a0fd7085053c71e78f3e0c187309b303
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tomcat@sha256:48afb9c9afcba1a1422bd3000e21f285899e44f760b517a54f9f7c80f761d33e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tomcat@sha256:65eb7d3695e6b1b0fbd754a20f1c9ede6ea45300d2756465d2fce0ed4939629a