Sign inSign up
Tomcat

dhi.io/tomcat

Tomcat 10.x JDK 17.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

10-jdk17-alpine3.23-fips-dev, 10.1-jdk17-alpine3.23-fips-dev, 10.1.60-jdk17-alpine3.23-fips-dev

Index digest:

sha256:6d0c063360dee559e68814776a456bdd300c9a93f3242886629de4e6ce9d3d4b

Manifest digest:

sha256:4711fc8f94fec81b61c846cc75bdfcdb525f11901a1e3bf2b7f913517e3cea54

Size

194.79 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tomcat:10-jdk17-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tomcat:10-jdk17-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tomcat@sha256:e9da51bf40be5ad632e7016929846a25d2b3d31cbb13346f1e25e302002b5f99
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tomcat@sha256:5b748d2e41e4852a43781910a523ad196a251b3a7cdd00060a7cb48fb4f7d9e2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tomcat@sha256:d6cc75769a488f664fbcc277ac253fe9bb562bc1f7132d84b5ebb6fe0b634157
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tomcat@sha256:41c284a8724a9850d975a66699608d9d79c142528b209cb8cccb9a8459c92b14
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tomcat@sha256:b67b305f753be42c155d2fe79df8191f82b74f13ce2b8f6e8d73dc818e56adcc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tomcat@sha256:33464f1382b5079777e1d6e4ebd621d8f96d9a1cd27c5235a8bdaeed3e06b46d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tomcat@sha256:a4586cbabc8c6bdb75e0543b45d21dcb04ac7bddc36bd381cca467ef66aa6ea6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tomcat@sha256:08f22f16cf92c3fe86ed78dde5f1b32d10f63d01089f60d199f5e1f8c124f1ce
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tomcat@sha256:07c882eb7f1592434c0d60a1cb97a8402a6a42f0f559d7cf60087defbcb030b7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tomcat@sha256:a99377c0a6e66761675383d1601d353c4622dd5bf7b8bef96b5e273daa06fe84
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tomcat@sha256:8ffbb4daa65e570a7770783e05b62de0aefedb2d9abfcae491baceb30e7b68e7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tomcat@sha256:98c53e4b3ca7a6ad4aa18736ac498804e40a782e5277ebeaefecd4f948c8088a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tomcat@sha256:a271776418e546950ec2ded3963154f976a5521dc17f20756b7b89db19e4ae2a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tomcat@sha256:79579286038527bfb1cf5093a3b1ce8c6b82495479d6fe96447a5614a3f9ea81
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tomcat@sha256:de563f5c7f73f51d121016c5783254dc3505b6be2c1dec1e2186303a9cfcad2c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tomcat@sha256:bf8a15a4adfb9f5a7f53b448d62b9fbe5f6ccae46f15c8b1ecf7e0d4abce5b53