Sign inSign up
Tomcat

dhi.io/tomcat

Tomcat 10.x JDK 25.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

10-jdk25-alpine-fips-dev, 10-jdk25-alpine3.24-fips-dev, 10.1-jdk25-alpine-fips-dev, 10.1-jdk25-alpine3.24-fips-dev, 10.1.60-jdk25-alpine-fips-dev, 10.1.60-jdk25-alpine3.24-fips-dev

Index digest:

sha256:9631d8a4c81cbe49912e338b82ed0cf20d06cd149b5e28f2ae3226b8ed5563a6

Manifest digest:

sha256:4ab239f8b4b9a04afdedf7c65ad1c2cfb8e91718c3a6aa16c74b7c40c2c5e681

Size

143.84 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tomcat:10-jdk25-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tomcat:10-jdk25-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tomcat@sha256:03acf4cc36a987cbae4ddf47afc7d1e80cd0b77b5d2c9ce46fe9f23aa64bb892
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tomcat@sha256:60634666d72a31d76d015d3d9af4205154e4ec43916d27fb42988a15ff22e933
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tomcat@sha256:2e89676aa8006fb5ec671dc1e6886cfd7859da6f35f9e818cd53cacfc3389ffe
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tomcat@sha256:7531dd47e36e6d80691daaf9b0a77bf46d310f7d038416454add3c16cbbe9af1
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tomcat@sha256:9236a50ea94070c375ea440afff46ca8f7472960f4e30cdb1a9509d86de31ef8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tomcat@sha256:e1eb86b96294bda0b50194397c6c49b63aaaccded939c03bcc34df7e3698d134
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tomcat@sha256:455d79f26e00085733031c46bfdef173dd8e0e9bf2db989d1680967f1487302c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tomcat@sha256:fd6586714f3535b7f8b88165c3cb2b28976e8ae7bdafafe5d6da2f2b02b01c79
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tomcat@sha256:19506c84ec682a8ec23c463f68bb943f88640aa8e756d069539956a4407ad7c6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tomcat@sha256:6ae9f91cdda4606da9ff13b06ead808e0a5a28bed89f92fb80c9e7346545bc24
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tomcat@sha256:4736988766b6519bd7c408e78ac770bf34885c94e4f00b4e0c7d990ab21d91df
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tomcat@sha256:0cd1610e3b34e9159ccdbdf01ae99be8ad76fb3b4ad3e15cb99867ae09b6c7b7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tomcat@sha256:6315a640ed1eaeaf94e8a45850c985a9b579a8ca2751fc207d7be55ecb6dfcf1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tomcat@sha256:5061a7df3b6d98c6e29c4730d25d140560b0ba4bcaa1f7c6ab89227a6dddabd6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tomcat@sha256:181eeea06f4a6b1b9e82c1790098ced5f7e919c1c73b5d1c1e85aedf23442723
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tomcat@sha256:013fe55ec6c73d0d69a38ce9b053a513a1bb98d7eadc7a4f10aad31c2937fc58