Sign inSign up
Tomcat

dhi.io/tomcat

Tomcat 10.x JDK 21.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

10-jdk21-debian-fips-dev, 10-jdk21-debian13-fips-dev, 10-jdk21-fips-dev, 10.1-jdk21-debian-fips-dev, 10.1-jdk21-debian13-fips-dev, 10.1-jdk21-fips-dev, 10.1.59-jdk21-debian-fips-dev, 10.1.59-jdk21-debian13-fips-dev, 10.1.59-jdk21-fips-dev

Index digest:

sha256:412d931bc57524cec5914a3af52bd892619a9ebc5c102ada492ab0539315a1c4

Manifest digest:

sha256:96160a2a370a783079fc9966b33727d192587a941ee70caa08fe06ad678bff51

Size

187.67 MB

Last pushed

4 hours ago

Vulnerabilities

1
2
0
14
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tomcat:10-jdk21-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tomcat:10-jdk21-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tomcat@sha256:43d63e886365f4b9ab338b5240c393258b2890aa79c93f525c8b607136dacf0a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tomcat@sha256:3681bcb3524adaa9898693b9abfef606f8e58591d54c72ed10d097fa026a8c85
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tomcat@sha256:cf900fe39a62c74b8b200feccf979b1578a29e6caebbd5b572bbdca2105a6ade
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tomcat@sha256:ce8a11b63b0003ee8628df99ce954a29542b3ad5d5963817eb6aa44ff95c238d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tomcat@sha256:93cccac455e34f90703269364f21d129901bc6465405d3438f7e90d26aa2d0a7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tomcat@sha256:944646453cc3f4b7ee9f05649a237a7d24abc1a667eeb813fcfedb59ba28a5d0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tomcat@sha256:791e14dd40a6140575ccba320b024233fefa8e24cefb70152d5e28cb37753d38
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tomcat@sha256:fbc81f0df73ae275ea20ac2c6d9d603e59ba129ea34d5771e3bcab69970d7e3b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tomcat@sha256:8b340302e591aefe58d7c04e701742622be73d5547f105acc93c7c693afdab7d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tomcat@sha256:9b84b9019392483157058009d4e4046efbff60ca282c039d175114835c59ff1a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tomcat@sha256:9a4e317386dacdbb1e4f1384f61fd5fc7442211ae37d01ec1e64f20506123517
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tomcat@sha256:9190a0044b29f959802c6dc51a983e58cb43b6084b093edac249127019b8fcad
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tomcat@sha256:4884fb5745db5e21d7ab498d1e3ce96f4d9c34b9b25e6b2d4a61f00b72bc8786
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tomcat@sha256:5ae4330018ac24f4b748f000964189ada9e3b09fe7e416dbac28794a046cb368
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tomcat@sha256:0f7ad8de5c71580e5588b7e9ed806ca20fd1eb6967084d08fc3958bc5e34aac1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tomcat@sha256:e7395fa1902c8879b98613ddf045e8140a478cd04f10078881d07d21e170ba22
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tomcat@sha256:0d99ef3a8400b9a35eeac700ca98373d001fb4455ba02027647df6794a461387