Sign inSign up
Tomcat

dhi.io/tomcat

Tomcat 10.x JDK 21.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

10-jdk21-debian-fips-dev, 10-jdk21-debian13-fips-dev, 10-jdk21-fips-dev, 10.1-jdk21-debian-fips-dev, 10.1-jdk21-debian13-fips-dev, 10.1-jdk21-fips-dev, 10.1.60-jdk21-debian-fips-dev, 10.1.60-jdk21-debian13-fips-dev, 10.1.60-jdk21-fips-dev

Index digest:

sha256:bf76ac59a29b312a1fec64139b050320f71f431b27d341bf77439b405a857e66

Manifest digest:

sha256:ed886f3987fd9ae6338c4257e4b4d8d5aaba27daac0f88e94b0314e185a84036

Size

187.76 MB

Last pushed

6 hours ago

Vulnerabilities

1
2
0
14
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tomcat:10-jdk21-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tomcat:10-jdk21-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tomcat@sha256:f05a2b92d8f97bf91e079c5036d193ebceca99424b0164da567a52924eef4ece
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tomcat@sha256:61d37d6d30a6a6a04f3b8faf6ff6c4edee8b2949f1d14d82b6ffd627b5f844aa
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tomcat@sha256:c5f7004acbf6023aadec8c21475cad50a64f6198091162bd673a33d2e72d6b6f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tomcat@sha256:d8f5aeee2923a8fccf105ed63d8143b381b62b22b45dd3f25f785a7f1ef8c355
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tomcat@sha256:515d6c053888385353dbc7e363345434c623a02df23497d4c35de3d138cbe5ce
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tomcat@sha256:56d64d2ed94ce9780afee99086d2383dbbc3c8f5cd577359a5745bf55a236aaf
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tomcat@sha256:55b013dd0bc98e8be40edbeeed3682b7d26360ffde98d809e445125b59da7c65
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tomcat@sha256:2458a220a428e9cba31b454de4c062a001609dc53654ca6ed0384aa3ff9e981c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tomcat@sha256:df492496c7d7e4b22a771f1abbefb5b7b60abcca9d1ee7a871f76a61616b1156
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tomcat@sha256:cf4e73620cc4733d87595aefcb0a3b87ddf024fd3dd03c4bbd8a62d73689b2bb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tomcat@sha256:406645716c8c11480cdffea8a97ec27977e72cf68940ea1bee95ae406d41cbea
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tomcat@sha256:e932cb4ac3e00b42f2cd515fe6a16aee16e275fa9b8cda3316cf889c2fbc03f0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tomcat@sha256:dc56df55d365aa58b9dc92413ea49404fe941a71f2a9f19bfb7abcf8fe7250b9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tomcat@sha256:f999c8e038195ad4e96c66e5849cd510bc26194076c050349b1284935ebb340a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tomcat@sha256:cb8fed83f824d66fe8e3335dec0e04b63a5e215596ab8a2544fc5465c7e3b027
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tomcat@sha256:732fc060c80ba7df36edfcbd92b2e9fcdce487ee7235233bcfae8633cdff128d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tomcat@sha256:a0d3518c7cb8aa1a5f4581df69d655e041178a2fcf322e799b2944e9954175f1