Sign inSign up
Tomcat

dhi.io/tomcat

Tomcat 11.x JDK 25.x (dev)

CIS
linux/amd64
debian 13
Tags:

11-jdk25-debian-dev, 11-jdk25-debian13-dev, 11-jdk25-dev, 11.0-jdk25-debian-dev, 11.0-jdk25-debian13-dev, 11.0-jdk25-dev, 11.0.26-jdk25-debian-dev, 11.0.26-jdk25-debian13-dev, 11.0.26-jdk25-dev

Index digest:

sha256:f95115afe6c015622b5a3af9994fe253350f3ed049ff2a2079b39720630ff5b6

Manifest digest:

sha256:4551b2de3a107cbc8f9c3a46b4e4ad9ce4d31122ed6cea3c7f24806205b6ecb6

Size

106.85 MB

Last pushed

8 hours ago

Vulnerabilities

0
2
0
13
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tomcat:11-jdk25-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tomcat:11-jdk25-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tomcat@sha256:548b606d8112b07406417a625a988e8bc131592af8d6d1f9a772cfc66d6718b6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tomcat@sha256:b0b1291d33177a3f380f013061f39e018d5670d2e19ab78ea7b30665bd54493e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tomcat@sha256:ce0c71277b9e49134b646f56f22acfe53ebf4e523e92ad47f4800b832d4c3b1c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tomcat@sha256:22303a537c93e88353afae7390c452bda0662b5d75189bc161c84082166a326b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tomcat@sha256:1e8f79e15a12638aa1fb58ace3a7a57bdd11c6f2da188208c75e30c6c42b5e35
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tomcat@sha256:73b9c932f3abed53c86c6be954b7e138392c8046c7c70596b2106a35e174a4c1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tomcat@sha256:4b6b5145cd8e8c9140b123d20ac733f8a3a810000dec07315cdf5d18a75542f1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tomcat@sha256:1bef10b13a5d4ab2a56ac019ddb03e8403465a0cee61b2c2eee90b284201006e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tomcat@sha256:ff15ec4536345b68b1b95c8024eb6d49fea830fac58ef65bd693f1f888ed80be
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tomcat@sha256:642b0e63966f842eba09b3448bfce3162bdb22dfa122c755faee481e338e2e50
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tomcat@sha256:abdb7f99929f343ebad8286a7c92ff96e86ac2a86d810a7754ec5b4c86d46dbd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tomcat@sha256:3e344cac56a224633b3c55b98b667f4ea896955eeddd9eef527336609d9d9842
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tomcat@sha256:821f5fe7c3d3672fcea50b438bebff702f6c8ba2b6ae57021adb83658ac5441c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tomcat@sha256:d384528c7837df883f3065cfa92c63596e480d02fb39be4af024d0ca4f13e9fe
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tomcat@sha256:602209c18f37ab55e47b6536a416876c8adefcbf2d93d2244245fc6b7a7576c9