dhi.io/tomcat
10-jdk25-alpine-fips-dev, 10-jdk25-alpine3.24-fips-dev, 10.1-jdk25-alpine-fips-dev, 10.1-jdk25-alpine3.24-fips-dev, 10.1.60-jdk25-alpine-fips-dev, 10.1.60-jdk25-alpine3.24-fips-dev
sha256:9631d8a4c81cbe49912e338b82ed0cf20d06cd149b5e28f2ae3226b8ed5563a6
Manifest digest:sha256:4ab239f8b4b9a04afdedf7c65ad1c2cfb8e91718c3a6aa16c74b7c40c2c5e681
Size
143.84 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tomcat:10-jdk25-alpine-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tomcat:10-jdk25-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tomcat@sha256:03acf4cc36a987cbae4ddf47afc7d1e80cd0b77b5d2c9ce46fe9f23aa64bb892 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tomcat@sha256:60634666d72a31d76d015d3d9af4205154e4ec43916d27fb42988a15ff22e933 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/tomcat@sha256:2e89676aa8006fb5ec671dc1e6886cfd7859da6f35f9e818cd53cacfc3389ffe |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tomcat@sha256:7531dd47e36e6d80691daaf9b0a77bf46d310f7d038416454add3c16cbbe9af1 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/tomcat@sha256:9236a50ea94070c375ea440afff46ca8f7472960f4e30cdb1a9509d86de31ef8 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tomcat@sha256:e1eb86b96294bda0b50194397c6c49b63aaaccded939c03bcc34df7e3698d134 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tomcat@sha256:455d79f26e00085733031c46bfdef173dd8e0e9bf2db989d1680967f1487302c |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tomcat@sha256:fd6586714f3535b7f8b88165c3cb2b28976e8ae7bdafafe5d6da2f2b02b01c79 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tomcat@sha256:19506c84ec682a8ec23c463f68bb943f88640aa8e756d069539956a4407ad7c6 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tomcat@sha256:6ae9f91cdda4606da9ff13b06ead808e0a5a28bed89f92fb80c9e7346545bc24 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tomcat@sha256:4736988766b6519bd7c408e78ac770bf34885c94e4f00b4e0c7d990ab21d91df |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tomcat@sha256:0cd1610e3b34e9159ccdbdf01ae99be8ad76fb3b4ad3e15cb99867ae09b6c7b7 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tomcat@sha256:6315a640ed1eaeaf94e8a45850c985a9b579a8ca2751fc207d7be55ecb6dfcf1 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tomcat@sha256:5061a7df3b6d98c6e29c4730d25d140560b0ba4bcaa1f7c6ab89227a6dddabd6 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tomcat@sha256:181eeea06f4a6b1b9e82c1790098ced5f7e919c1c73b5d1c1e85aedf23442723 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tomcat@sha256:013fe55ec6c73d0d69a38ce9b053a513a1bb98d7eadc7a4f10aad31c2937fc58 |