dhi.io/tomcat
10-jdk25-debian-dev, 10-jdk25-debian13-dev, 10-jdk25-dev, 10.1-jdk25-debian-dev, 10.1-jdk25-debian13-dev, 10.1-jdk25-dev, 10.1.60-jdk25-debian-dev, 10.1.60-jdk25-debian13-dev, 10.1.60-jdk25-dev
sha256:716bae97ac469bc0edb1d3df11be67d45b862520003d6e2604074fc2ec789dec
Manifest digest:sha256:f5dfe3ed30dc32f31278ecd1b955963d9bd4d757b761015769a6d300138d4ded
Size
106.77 MB
Last pushed
8 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tomcat:10-jdk25-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tomcat:10-jdk25-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tomcat@sha256:68f580e13b40073178925fbd798cca5ac9f76ce01b942077c9d9b008f5156653 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tomcat@sha256:144923763e601185433a00f9f78b9ac7fcb970d87a14b1b97dd3d9666835c453 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tomcat@sha256:8a312b488d74d09f46088cb097cf4255807a21d7e56cb8962bae27e4ecadb41e |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tomcat@sha256:3605189cf151c2bbdaa1e1275be24b1f4bc2ed180fa63dd7fecef68bae00712e |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/tomcat@sha256:f990cee31a1e401277e00bae45a6f9afcc1fa733de5efa99c0ba6b433d740fb8 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tomcat@sha256:8a1df99e21ed846f540cdd97149e9c166c8724c3d87e4a2a009419db1fd99460 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tomcat@sha256:e6d15d6774b9e28853ed145b542cf88621c6b87d9f4889c433ff788efc3d45e5 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tomcat@sha256:1fff615f2d341e5152b05105e74e3170df7ee5dbe44649076e58c870bcf262fb |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tomcat@sha256:d5e68810ccf7a64f33a3d96b7403bccc5cbe0fc68d74c061838ac98c2c6bd459 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tomcat@sha256:fc78a5985488b0ec4b93532c32021066e58a6b386b367dfc9e97f46dc158801f |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tomcat@sha256:03a75572aff845079377238ca255949363d916d4181814d8e3692500ddf6d9ba |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tomcat@sha256:b68a5b1ebdbefeeb13b0b2674cbe7cd41bc0c0f4abd211afb9f54f538247d87c |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tomcat@sha256:279942b5f91ed3da9ac6a4eb6417fb11a0fd7085053c71e78f3e0c187309b303 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tomcat@sha256:48afb9c9afcba1a1422bd3000e21f285899e44f760b517a54f9f7c80f761d33e |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tomcat@sha256:65eb7d3695e6b1b0fbd754a20f1c9ede6ea45300d2756465d2fce0ed4939629a |