Sign inSign up
Tomcat

dhi.io/tomcat

Tomcat 9.x JDK 21.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

9-jdk21-alpine-fips, 9-jdk21-alpine3.24-fips, 9.0-jdk21-alpine-fips, 9.0-jdk21-alpine3.24-fips, 9.0.122-jdk21-alpine-fips, 9.0.122-jdk21-alpine3.24-fips

Index digest:

sha256:cd5a6877e9092620b33e3709c51c6be1bddf696ab75747d2f1b30cdb04343b42

Manifest digest:

sha256:895573bcbb0bb2f7b0a290e5e502e69c83a3993e5b93598094ee7ad0e2eb0b2e

Size

64.27 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tomcat:9-jdk21-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tomcat:9-jdk21-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tomcat@sha256:1d0b1e1eff17d538e191e9d7c3d8bbb2d0b0725a68ace1131294e80aff647e18
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tomcat@sha256:cf9e017a05de04d113351cb1c4b402187748b0f1bcfe55585920f67486c8def3
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tomcat@sha256:e1f16ff066f8280358f41bd3f577c5c2f8239677c311c4c8806a30f4e30a46fe
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tomcat@sha256:1be685a8a9c2559cce32a134c4129e15eb8e0fe4ad156d5158c73b6c5a52616d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tomcat@sha256:3960ba58218f884c86fbea5ca217ffd23b96df5c0cacb3efeafa4ae8cc67de73
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tomcat@sha256:77acb13cc246f73898757d1cae0f281b20f6e0bd5a9f8922be8be2a690a9e25a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tomcat@sha256:71dead64cfdc0a5debb0975a1457dd86e2f2540cfff55e6750f821c66ebf83e3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tomcat@sha256:211df5b11b5b65b3a1ded19ea188d0ae53a757b1362f61057fce84780f4ab15d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tomcat@sha256:28d2923792a4c14b84a2e46f8a17a0c7c75fea2f51c95f09fed2767570f7a6e8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tomcat@sha256:89e53b4c3c87c8fc894b555a840fb4a83813f006741e11cf85491aeca994d4f7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tomcat@sha256:b99380360d2139e1ccf6ddeacfe4ac39626e4b782e91c0b8ac702c74b900256a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tomcat@sha256:90751814b7359a849adc43f1c0ca6a37fedff3f2f03ec9ceed97222fb743716c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tomcat@sha256:676d6ebdbb622e164f5dbb142e7345df2bc7c3f7343a23525c9567b991c4a8c1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tomcat@sha256:87cf7569593c4dce9830ba565f4602c8b766c756cc0fe2284700c4c70deba598
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tomcat@sha256:c7b0dcc4f79678828867ca22499c79e3703cdb078c80e87321a07800f08cec2c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tomcat@sha256:b0f4fe406cbf823c05921012813630d373654dd3c143bfa2786b8bb76dce80f9