dhi.io/tomcat
10-jdk25-debian-fips-dev, 10-jdk25-debian13-fips-dev, 10-jdk25-fips-dev, 10.1-jdk25-debian-fips-dev, 10.1-jdk25-debian13-fips-dev, 10.1-jdk25-fips-dev, 10.1.60-jdk25-debian-fips-dev, 10.1.60-jdk25-debian13-fips-dev, 10.1.60-jdk25-fips-dev
sha256:228f75a4e52bf063300a128b82490be5bd4bb9e8c9d637c609987c2ebb77df02
Manifest digest:sha256:ea4cb258024adeab3c1931549e804fcee435425a2e6e61c5610bdffe09933c5d
Size
122.96 MB
Last pushed
9 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tomcat:10-jdk25-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tomcat:10-jdk25-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tomcat@sha256:984ee52b2e80e04fc24aef162735c964be4d9579fe96e5eaabcba0b3e245efc3 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tomcat@sha256:e9ba0284d35ced287b0ed9bd7b137f454558222d7756237cba816a30a3496b22 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/tomcat@sha256:964e4dc23e854df139424abb49d12c569dcbda6f8e137b41d80d1998ebbca8be |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tomcat@sha256:e28d103905c43af90ebe71f5ef4a36d25bfeb763a0a5ede7b77b0526c4ce26e3 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/tomcat@sha256:e343211f72f723440b839cdd13723fce4db5acf6b1f77fc868a3aa9ac55f5443 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tomcat@sha256:041372c5eb41f207ff446f929e053f5766ba553190a3cb13b4ec1e922546a34b |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/tomcat@sha256:fd4e84f2758273d2bebccce4fcd68fd9a70c823f324ab1e9ab50f4173055e5b6 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tomcat@sha256:0d1ea08742eee69a00622af23e2f1c38117a5fb109d8d7d4dc47cc9e58ca4ada |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tomcat@sha256:0e90be1a3ee623d1ac1a06cf9e3e705bea89a26061e9f96627d8dd20cfc9573c |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tomcat@sha256:7e5c6ca0b50b7134b993a69a33eb61e94df0016ce394ee7099d48cc8ff59a03c |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tomcat@sha256:dd3d5faa709f7a977bd9c1e881634974f8d56f680f9aaffe0513ea861c44b6e2 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tomcat@sha256:9d8bb343236e328ee2e5328939285ad5784766c76f0b04559dbc4f5dec7be980 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tomcat@sha256:662f48966ca3f8b117459b768a5af4e78cea6654613106af5727cb37ea8b89bb |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tomcat@sha256:5db5f27f168adfb6ae8150d65197cfd25c43a5f959ae5a6f87839dc51a920be5 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tomcat@sha256:d27a2c93349be9292ab8813ada1c18f6e288ba1d0950cf132f29ec13997c6e21 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tomcat@sha256:06db081388b17ca1cba92022b8641e326bcd017506f7afc8000a7f2d34188df9 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tomcat@sha256:0676f057ede99213747da652e895cac9061a6c2a9ee6a49a936deb213230df9f |