Sign inSign up
Tomcat

dhi.io/tomcat

Tomcat 10.x JDK 17.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

10-jdk17-debian-fips-dev, 10-jdk17-debian13-fips-dev, 10-jdk17-fips-dev, 10.1-jdk17-debian-fips-dev, 10.1-jdk17-debian13-fips-dev, 10.1-jdk17-fips-dev, 10.1.60-jdk17-debian-fips-dev, 10.1.60-jdk17-debian13-fips-dev, 10.1.60-jdk17-fips-dev

Index digest:

sha256:395161676213f1b7fb925cc832814443f2ccc8f6192d0249c31b9ceae0988cf4

Manifest digest:

sha256:9105a9ea42e5392ade28310136ea84203cb246bcd5d1575ef8dfc8dff366b6f8

Size

175.28 MB

Last pushed

3 days ago

Vulnerabilities

0
2
0
14
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tomcat:10-jdk17-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tomcat:10-jdk17-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tomcat@sha256:0aee6d2aa84a54544443ba77140a99ea41b30f8bfaacb79655d1ca60bba4b97e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tomcat@sha256:7a3d33a596c351efea2cae99385c89983d59fbd000855eafa027e563d83bd3be
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tomcat@sha256:82ad1a16a7b111abb20c2b25ee3f3f4a43ec6dc7206482b204d60b6b7989c78b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tomcat@sha256:e5c696766e4e31e4cdf677236f7732eca12c090d854fcc6f2c1ab0400744ade6
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tomcat@sha256:6a44e78487af8513f198c841e0ad79680ebd9a90d10b2c993987387813b5e07e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tomcat@sha256:9286584d8adad0ca2543de586212e3d1b665c59d65405c4c0c8fb4237a901f60
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tomcat@sha256:98a7c8495e8431848101c1a36e8af933bf3195423721bfbcb91f924f2a283eed
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tomcat@sha256:7ec2fc6ecb4ea3683441b44beda65d23b00cfcf5329d3d866fec4621b952a017
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tomcat@sha256:dc30c89f880c2b0ea927530e31aad2e09ab5ecc35cb81311855210368b419aa0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tomcat@sha256:d8aa1b019ef6ca15665ab9fcc7e59a40e2e991391e49cf7348c8d0c9498978f0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tomcat@sha256:0ad39b0ff517d888496a58748df36cd2ceb088a523789bd3001b3a1c346ff681
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tomcat@sha256:a97582550636dc8e0871d130fcf6d94edf15f88c4bbc39e0331cbcb2de341443
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tomcat@sha256:a6420b347e8f2e13f35fb766fed97bc94f113452daf4766a2d50c318af48856e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tomcat@sha256:caf391a87ed29e1edbde5562fb5c51c1ffdf1f7714363c1373bad9bd4b96ec63
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tomcat@sha256:c7279478cc0fda0297bc62ac21e1908a7c12385d16ed6388d2f2c291ab425249
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tomcat@sha256:0731e247d4c19ec0df718b893523c8645858264b1aec2d5b44c37956568cfaf9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tomcat@sha256:9a53afcc214859769d4dbfce26283c9578a4a5b38fa45a03fda160b1d90d7b4b