Sign inSign up
Tomcat

dhi.io/tomcat

Tomcat 10.x JDK 25.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

10-jdk25-alpine-fips, 10-jdk25-alpine3.24-fips, 10.1-jdk25-alpine-fips, 10.1-jdk25-alpine3.24-fips, 10.1.60-jdk25-alpine-fips, 10.1.60-jdk25-alpine3.24-fips

Index digest:

sha256:0986862ae4b549908c1457410ece00540414c34010486e35d8ccf411b5d1b707

Manifest digest:

sha256:4fd26c4a4c1dcd970e42d71f3cca21a028b33349bb15e82773b732ec2232b1e8

Size

72.79 MB

Last pushed

4 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tomcat:10-jdk25-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tomcat:10-jdk25-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tomcat@sha256:5bfd3c2328606fe3ed96e4a5051644737c206fec86d8a78c7b128dda4a7be196
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tomcat@sha256:8d7e476f3a384aaf591e46481c00f7e22fa9753e1e94d0830e680d4d5b4523d9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tomcat@sha256:b85b687f9ce1ea0a2e80fac7012be0c40cc3dae523f63120d6904bfa0bf0e8df
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tomcat@sha256:6846aa7ff40a9be3e2ee307077ed3eb288ea7ed48f9db4a4505790a1f561c211
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tomcat@sha256:d8874af3b3ba85da70eb8b6fe18d5b84e8e5e5374a109ebce3272990c0eb1232
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tomcat@sha256:eb1d72ec6b963ff68d12139f51f1cc349993c39470695ea7108d0e70b2ea0887
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tomcat@sha256:afd554590aeedfe48168787b373fa99f1e5021807c679c3262c0331e5f9ef2c4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tomcat@sha256:b330f0c9b475c8cd3ab74991c04167e1d02abca1004ffeb41e0bf20f78cfebe1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tomcat@sha256:4cf7b846c88ae69eab8779188525dbce60ca8abb03b92365cfbb5c7e934c0d4a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tomcat@sha256:0b295781513d6cb5fa897b46c490295b506272a48b98c42843f6e6a9b0e27d13
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tomcat@sha256:6cbf0c30e6249d697d60d51043d16ea479a37e5b1c484e90434890d0c7d51a01
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tomcat@sha256:86466147c66111a9f1d038eae7641aa46fb655a078d04147a107069f019f1e25
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tomcat@sha256:97c23a3d94e29195ac88252dba7bdea7df77c406abaa4b9c7c939b69b6aa1414
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tomcat@sha256:5bdf31ded8c0fb4db5f2e60970c51299601088c22f47ad3cceb443ccb26600c7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tomcat@sha256:7cfbb82d2a03e7ad8a4ced29019ea5d93eca6683a578c8f49d6738c02228cd9b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tomcat@sha256:1fb7aa0c7e1b7de11bed89626b4e5a907c6794d820c003cf2e45be397426d4bf