Sign inSign up
Tomcat

dhi.io/tomcat

Tomcat 11.x JDK 25.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

11-jdk25-alpine-fips-dev, 11-jdk25-alpine3.24-fips-dev, 11.0-jdk25-alpine-fips-dev, 11.0-jdk25-alpine3.24-fips-dev, 11.0.26-jdk25-alpine-fips-dev, 11.0.26-jdk25-alpine3.24-fips-dev

Index digest:

sha256:c74bbc98f921e2c8e5d260b50a70c4ed953df51b464f3d77db9d45a99d7065df

Manifest digest:

sha256:641dd06b2f74e5f73422ca6000ff5eeacaddf4968b9e5ab45d113b4b21aae57b

Size

143.92 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tomcat:11-jdk25-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tomcat:11-jdk25-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tomcat@sha256:fc55130025f827772459676d549654d7c0209f48c184f8b85081c73713ceb977
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tomcat@sha256:8e5dc01b8fd926fade69e70d5ad187cce1effac335356be0b4e3106534ee12fb
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tomcat@sha256:41561c5b984d596dc8c2102f1a2394282b3973f8d0c501489b20259e9102b82c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tomcat@sha256:29a1c2d00f6a1991d7c239e47f464c183b246ccabdc1884a530c622f2b65cace
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tomcat@sha256:439731fc2340d8343aa8ad8192ab4ac93258f95aff9a2a215e4c8c03808d2dd6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tomcat@sha256:3ab38c3e3bae8da1fcaa72c9584a4cf627fc062b459230fb65b3ffd773fd770e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tomcat@sha256:603267d145d8333b8bccdaa4ea0462d0a6dd010d1ec9755561b17274c23122c9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tomcat@sha256:92076e4a8dc830b1e2e7913fa016e3327039f51cd850f75c1ee6a0d8b87e0f18
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tomcat@sha256:a00523125b5237cf03efafd695bc63f48dc055ea06c8fc8c7bc9983cf74a1032
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tomcat@sha256:2af1eb44b5ade0155ca52d9ac9f180c50e94d80c9750ccac17fb7eb654fc2906
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tomcat@sha256:1500aaaa8bf9a53b013123c38f962e4ab51f3766e74c9bff277e6f9d1af6c9b4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tomcat@sha256:bb770d3b4c28941201666be863f58443cba2144b7657c3b0b33180b34f76ad1f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tomcat@sha256:d6aa9752ca2cf8c494f2eb613013799338fdaeb53ea96833d4aead3ea123ec21
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tomcat@sha256:c1add79a43d41b71d5f33033eb979b662d74435ce59b2783780f2183b9ee7558
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tomcat@sha256:5dd9da71f21590d7ea524411f2a9c37384288d2b30eb8469103b5cf745c980ed
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tomcat@sha256:8c66a08cd91671f3601e0385e26eabe04d8cec4cbd8007e6fcdd33ac5355f998