Sign inSign up
Tomcat

dhi.io/tomcat

Tomcat 10.x JDK 25.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

10-jdk25-debian-fips-dev, 10-jdk25-debian13-fips-dev, 10-jdk25-fips-dev, 10.1-jdk25-debian-fips-dev, 10.1-jdk25-debian13-fips-dev, 10.1-jdk25-fips-dev, 10.1.60-jdk25-debian-fips-dev, 10.1.60-jdk25-debian13-fips-dev, 10.1.60-jdk25-fips-dev

Index digest:

sha256:228f75a4e52bf063300a128b82490be5bd4bb9e8c9d637c609987c2ebb77df02

Manifest digest:

sha256:ea4cb258024adeab3c1931549e804fcee435425a2e6e61c5610bdffe09933c5d

Size

122.96 MB

Last pushed

9 hours ago

Vulnerabilities

0
1
0
7
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tomcat:10-jdk25-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tomcat:10-jdk25-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tomcat@sha256:984ee52b2e80e04fc24aef162735c964be4d9579fe96e5eaabcba0b3e245efc3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tomcat@sha256:e9ba0284d35ced287b0ed9bd7b137f454558222d7756237cba816a30a3496b22
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tomcat@sha256:964e4dc23e854df139424abb49d12c569dcbda6f8e137b41d80d1998ebbca8be
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tomcat@sha256:e28d103905c43af90ebe71f5ef4a36d25bfeb763a0a5ede7b77b0526c4ce26e3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tomcat@sha256:e343211f72f723440b839cdd13723fce4db5acf6b1f77fc868a3aa9ac55f5443
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tomcat@sha256:041372c5eb41f207ff446f929e053f5766ba553190a3cb13b4ec1e922546a34b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tomcat@sha256:fd4e84f2758273d2bebccce4fcd68fd9a70c823f324ab1e9ab50f4173055e5b6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tomcat@sha256:0d1ea08742eee69a00622af23e2f1c38117a5fb109d8d7d4dc47cc9e58ca4ada
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tomcat@sha256:0e90be1a3ee623d1ac1a06cf9e3e705bea89a26061e9f96627d8dd20cfc9573c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tomcat@sha256:7e5c6ca0b50b7134b993a69a33eb61e94df0016ce394ee7099d48cc8ff59a03c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tomcat@sha256:dd3d5faa709f7a977bd9c1e881634974f8d56f680f9aaffe0513ea861c44b6e2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tomcat@sha256:9d8bb343236e328ee2e5328939285ad5784766c76f0b04559dbc4f5dec7be980
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tomcat@sha256:662f48966ca3f8b117459b768a5af4e78cea6654613106af5727cb37ea8b89bb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tomcat@sha256:5db5f27f168adfb6ae8150d65197cfd25c43a5f959ae5a6f87839dc51a920be5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tomcat@sha256:d27a2c93349be9292ab8813ada1c18f6e288ba1d0950cf132f29ec13997c6e21
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tomcat@sha256:06db081388b17ca1cba92022b8641e326bcd017506f7afc8000a7f2d34188df9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tomcat@sha256:0676f057ede99213747da652e895cac9061a6c2a9ee6a49a936deb213230df9f