dhi.io/tomcat
9-jdk21-alpine-fips, 9-jdk21-alpine3.24-fips, 9.0-jdk21-alpine-fips, 9.0-jdk21-alpine3.24-fips, 9.0.122-jdk21-alpine-fips, 9.0.122-jdk21-alpine3.24-fips
sha256:cd5a6877e9092620b33e3709c51c6be1bddf696ab75747d2f1b30cdb04343b42
Manifest digest:sha256:895573bcbb0bb2f7b0a290e5e502e69c83a3993e5b93598094ee7ad0e2eb0b2e
Size
64.27 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tomcat:9-jdk21-alpine-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tomcat:9-jdk21-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tomcat@sha256:1d0b1e1eff17d538e191e9d7c3d8bbb2d0b0725a68ace1131294e80aff647e18 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tomcat@sha256:cf9e017a05de04d113351cb1c4b402187748b0f1bcfe55585920f67486c8def3 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/tomcat@sha256:e1f16ff066f8280358f41bd3f577c5c2f8239677c311c4c8806a30f4e30a46fe |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tomcat@sha256:1be685a8a9c2559cce32a134c4129e15eb8e0fe4ad156d5158c73b6c5a52616d |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/tomcat@sha256:3960ba58218f884c86fbea5ca217ffd23b96df5c0cacb3efeafa4ae8cc67de73 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tomcat@sha256:77acb13cc246f73898757d1cae0f281b20f6e0bd5a9f8922be8be2a690a9e25a |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tomcat@sha256:71dead64cfdc0a5debb0975a1457dd86e2f2540cfff55e6750f821c66ebf83e3 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tomcat@sha256:211df5b11b5b65b3a1ded19ea188d0ae53a757b1362f61057fce84780f4ab15d |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tomcat@sha256:28d2923792a4c14b84a2e46f8a17a0c7c75fea2f51c95f09fed2767570f7a6e8 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tomcat@sha256:89e53b4c3c87c8fc894b555a840fb4a83813f006741e11cf85491aeca994d4f7 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tomcat@sha256:b99380360d2139e1ccf6ddeacfe4ac39626e4b782e91c0b8ac702c74b900256a |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tomcat@sha256:90751814b7359a849adc43f1c0ca6a37fedff3f2f03ec9ceed97222fb743716c |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tomcat@sha256:676d6ebdbb622e164f5dbb142e7345df2bc7c3f7343a23525c9567b991c4a8c1 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tomcat@sha256:87cf7569593c4dce9830ba565f4602c8b766c756cc0fe2284700c4c70deba598 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tomcat@sha256:c7b0dcc4f79678828867ca22499c79e3703cdb078c80e87321a07800f08cec2c |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tomcat@sha256:b0f4fe406cbf823c05921012813630d373654dd3c143bfa2786b8bb76dce80f9 |