Sign inSign up
Tomcat

dhi.io/tomcat

Tomcat 11.x JDK 25.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

11-jdk25-alpine3.23-fips-dev, 11.0-jdk25-alpine3.23-fips-dev, 11.0.26-jdk25-alpine3.23-fips-dev

Index digest:

sha256:12be7a1f6c535a1d9a55f188cfb6801a36480f20d2d71994e09abe397eef0a0c

Manifest digest:

sha256:40b6a5ba9c0b47c9c85c0c4f7e8b95884a1c5a1e207298e2738f857599b0ad50

Size

143.90 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tomcat:11-jdk25-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tomcat:11-jdk25-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tomcat@sha256:e73552cbc2d6697edea21d34f145c5d5c258cd2cf0ba5a82a43aed54c464fb62
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tomcat@sha256:5b72c73c9fad319c716d145454a6b8712bf2c91f9f0fdf6ae3f40883d512b79b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tomcat@sha256:6756f6ac6439ef1873ff9f21780215744921783d996a1ade4159b3d632a103e7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tomcat@sha256:e0e1d1d9445136bdd0270ef5522e58de63a5332bad1dd0d5bde054881e036d69
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tomcat@sha256:1b8a59c5ad793ce880ef5c6c05f2ab8b8ab94499ff607eac35aef1b85e8a64cd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tomcat@sha256:d5fb8dd3c5b4421691a1406c6201ec57ea0ac5b9a508ec83837f942ecf54a6a4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tomcat@sha256:b56cd2f65948218acecc6bcd09c964f3fbe81152201f12e4d6cbc8e391e0026b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tomcat@sha256:7d648d3fba710a799bbaa51248796f5992d9646b03249b141e7c15cdf1c5463e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tomcat@sha256:04900160a7df97f825184f50a5dba8da5a6f90143be027e7968c63a09563c51d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tomcat@sha256:9098cd18a67daca0407308bd9103a0fc63a281bc14ce586bcceff7952461ea87
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tomcat@sha256:a44cf705b8582e1b6d32d5c9793493afec9a80191361aa380debf2b3b6cdd1b7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tomcat@sha256:16be9a167486fe16e5475ae96e2165158d56261925b7489fa53428bd5939ae19
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tomcat@sha256:64d17b93ea91935e43422358061739699b9fce335c9cfdd5ce6b2d24630d4a36
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tomcat@sha256:7ebe36263c3076e1ca2c519dc5c3a3ed1610b433ed49976021c0039dc152e6fd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tomcat@sha256:869c6a03fb232b158a7bb4e3e316d911c23f3641ec128de1c325393958ae9095
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tomcat@sha256:6f63022a80c1c47c32ae826cf22710a705155822c173a381c9eea0ab4c9902b7