Sign inSign up
Tomcat

dhi.io/tomcat

Tomcat 10.x JDK 17.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

10-jdk17-alpine3.23-fips-dev, 10.1-jdk17-alpine3.23-fips-dev, 10.1.60-jdk17-alpine3.23-fips-dev

Index digest:

sha256:bddbfe7ee0440fc35ff0cd0d93217b1171a67af9ed38d36876f598a00fb0da76

Manifest digest:

sha256:e15aac8a998703167b9c263220b4d321e133fb2bb72aa1ab74670b51982eac75

Size

194.79 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tomcat:10-jdk17-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tomcat:10-jdk17-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tomcat@sha256:97ab3f15a87ec20555a4ee7032f2563b2b2ef510324e0d348b890534aae290a7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tomcat@sha256:f38143c64d7269673c95008936f09aee351f9bd82a611bf6d376f72d23392607
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tomcat@sha256:9d8e90dc9fa515e68a5fd3c3fb79259d5aebb2525ca0fdb83c040d9cc4484eb5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tomcat@sha256:9dbd775e614f2c5416d32f560108a57f2fc14d142a836297dd7eaa9d8fa211a7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tomcat@sha256:db9af7545901898e194b98cf8c0a1a570acead7337eb73930a0b2faf09070317
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tomcat@sha256:49efa358b1229e8674fc5ac1ff2d213e13c9a24f83ba1e2f3d6dbb409a9a502d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tomcat@sha256:c6ba93d30c03f3b3b97353834636cd6b2640b5647f10dae1e81a0cef3d0ddd6f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tomcat@sha256:9e124082421e32b8ec8370a6353daaa8d77f910c5987c726e6dd82ad521dc577
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tomcat@sha256:7b047b5c8e5961852d51982b05c520b9806cc02cab8dc80610c2fb921ff0b28b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tomcat@sha256:cd1d5306564153f2af9bc318e4e036b94fd925b1ac0f3255e9bc923f2a870c57
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tomcat@sha256:ae40eff0a32a70c7ddfc49509b0a48fba3a7d4f1227b4480644fb9c82b889dac
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tomcat@sha256:74aca4221665ca9e8439a9182d35aabf162ad5a716740dc16a090a0e106655d0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tomcat@sha256:ed3a978350b7f8ab83cb0b4e995f31213fd0261508ad5719b3c7408d009b4683
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tomcat@sha256:514f47d03127779ba3ddfe6a02b64b0bc1291f4559a8af983de41f98418aeade
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tomcat@sha256:22b72dce7181fc2bfccd8ecd9ab7119625dad604da49c0359d54d418fd3b4a66
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tomcat@sha256:3ee881b07d10105f4f116c38e1859cf6bac3cba486a7719304ebb6165916bebe