dhi.io/tomcat
11-jdk25-alpine-fips-dev, 11-jdk25-alpine3.24-fips-dev, 11.0-jdk25-alpine-fips-dev, 11.0-jdk25-alpine3.24-fips-dev, 11.0.26-jdk25-alpine-fips-dev, 11.0.26-jdk25-alpine3.24-fips-dev
sha256:c74bbc98f921e2c8e5d260b50a70c4ed953df51b464f3d77db9d45a99d7065df
Manifest digest:sha256:641dd06b2f74e5f73422ca6000ff5eeacaddf4968b9e5ab45d113b4b21aae57b
Size
143.92 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tomcat:11-jdk25-alpine-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tomcat:11-jdk25-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tomcat@sha256:fc55130025f827772459676d549654d7c0209f48c184f8b85081c73713ceb977 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tomcat@sha256:8e5dc01b8fd926fade69e70d5ad187cce1effac335356be0b4e3106534ee12fb |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/tomcat@sha256:41561c5b984d596dc8c2102f1a2394282b3973f8d0c501489b20259e9102b82c |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tomcat@sha256:29a1c2d00f6a1991d7c239e47f464c183b246ccabdc1884a530c622f2b65cace |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/tomcat@sha256:439731fc2340d8343aa8ad8192ab4ac93258f95aff9a2a215e4c8c03808d2dd6 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tomcat@sha256:3ab38c3e3bae8da1fcaa72c9584a4cf627fc062b459230fb65b3ffd773fd770e |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tomcat@sha256:603267d145d8333b8bccdaa4ea0462d0a6dd010d1ec9755561b17274c23122c9 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tomcat@sha256:92076e4a8dc830b1e2e7913fa016e3327039f51cd850f75c1ee6a0d8b87e0f18 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tomcat@sha256:a00523125b5237cf03efafd695bc63f48dc055ea06c8fc8c7bc9983cf74a1032 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tomcat@sha256:2af1eb44b5ade0155ca52d9ac9f180c50e94d80c9750ccac17fb7eb654fc2906 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tomcat@sha256:1500aaaa8bf9a53b013123c38f962e4ab51f3766e74c9bff277e6f9d1af6c9b4 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tomcat@sha256:bb770d3b4c28941201666be863f58443cba2144b7657c3b0b33180b34f76ad1f |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tomcat@sha256:d6aa9752ca2cf8c494f2eb613013799338fdaeb53ea96833d4aead3ea123ec21 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tomcat@sha256:c1add79a43d41b71d5f33033eb979b662d74435ce59b2783780f2183b9ee7558 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tomcat@sha256:5dd9da71f21590d7ea524411f2a9c37384288d2b30eb8469103b5cf745c980ed |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tomcat@sha256:8c66a08cd91671f3601e0385e26eabe04d8cec4cbd8007e6fcdd33ac5355f998 |