dhi.io/tomcat
10-jdk21-debian-fips-dev, 10-jdk21-debian13-fips-dev, 10-jdk21-fips-dev, 10.1-jdk21-debian-fips-dev, 10.1-jdk21-debian13-fips-dev, 10.1-jdk21-fips-dev, 10.1.59-jdk21-debian-fips-dev, 10.1.59-jdk21-debian13-fips-dev, 10.1.59-jdk21-fips-dev
sha256:412d931bc57524cec5914a3af52bd892619a9ebc5c102ada492ab0539315a1c4
Manifest digest:sha256:96160a2a370a783079fc9966b33727d192587a941ee70caa08fe06ad678bff51
Size
187.67 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tomcat:10-jdk21-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tomcat:10-jdk21-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tomcat@sha256:43d63e886365f4b9ab338b5240c393258b2890aa79c93f525c8b607136dacf0a |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tomcat@sha256:3681bcb3524adaa9898693b9abfef606f8e58591d54c72ed10d097fa026a8c85 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/tomcat@sha256:cf900fe39a62c74b8b200feccf979b1578a29e6caebbd5b572bbdca2105a6ade |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tomcat@sha256:ce8a11b63b0003ee8628df99ce954a29542b3ad5d5963817eb6aa44ff95c238d |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/tomcat@sha256:93cccac455e34f90703269364f21d129901bc6465405d3438f7e90d26aa2d0a7 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tomcat@sha256:944646453cc3f4b7ee9f05649a237a7d24abc1a667eeb813fcfedb59ba28a5d0 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/tomcat@sha256:791e14dd40a6140575ccba320b024233fefa8e24cefb70152d5e28cb37753d38 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tomcat@sha256:fbc81f0df73ae275ea20ac2c6d9d603e59ba129ea34d5771e3bcab69970d7e3b |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tomcat@sha256:8b340302e591aefe58d7c04e701742622be73d5547f105acc93c7c693afdab7d |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tomcat@sha256:9b84b9019392483157058009d4e4046efbff60ca282c039d175114835c59ff1a |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tomcat@sha256:9a4e317386dacdbb1e4f1384f61fd5fc7442211ae37d01ec1e64f20506123517 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tomcat@sha256:9190a0044b29f959802c6dc51a983e58cb43b6084b093edac249127019b8fcad |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tomcat@sha256:4884fb5745db5e21d7ab498d1e3ce96f4d9c34b9b25e6b2d4a61f00b72bc8786 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tomcat@sha256:5ae4330018ac24f4b748f000964189ada9e3b09fe7e416dbac28794a046cb368 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tomcat@sha256:0f7ad8de5c71580e5588b7e9ed806ca20fd1eb6967084d08fc3958bc5e34aac1 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tomcat@sha256:e7395fa1902c8879b98613ddf045e8140a478cd04f10078881d07d21e170ba22 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tomcat@sha256:0d99ef3a8400b9a35eeac700ca98373d001fb4455ba02027647df6794a461387 |