Sign inSign up
Tomcat

dhi.io/tomcat

Tomcat 10.x JDK 17.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

10-jdk17-debian-fips-dev, 10-jdk17-debian13-fips-dev, 10-jdk17-fips-dev, 10.1-jdk17-debian-fips-dev, 10.1-jdk17-debian13-fips-dev, 10.1-jdk17-fips-dev, 10.1.60-jdk17-debian-fips-dev, 10.1.60-jdk17-debian13-fips-dev, 10.1.60-jdk17-fips-dev

Index digest:

sha256:8da8073ab64aa136f74db21cc3c224a7c20717326f221ff9a319d9274732d7c3

Manifest digest:

sha256:9613c58156de08f4532a590ac000c76e3d8b1d45bbc971e4eb0e4461ed001a30

Size

178.56 MB

Last pushed

12 hours ago

Vulnerabilities

1
2
0
14
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tomcat:10-jdk17-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tomcat:10-jdk17-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tomcat@sha256:dbad7292f58172b9a11b71ac5fdb6965df1da43c6658d531a6c4569a0efc7403
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tomcat@sha256:8357728c87b4ea040067bee200dd147820a03f6f35459194ca7e7d98f27aa54b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tomcat@sha256:fe88b7d27b624a426270031e0638d7b78ab663258ae187e7f7914230453071d1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tomcat@sha256:2cbfbf1daf5a38559d5b310117ef7d606f7dbcbc8dda0eff1847d38cee93c7c0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tomcat@sha256:f3595d6180a710c5b172183bd1e4c27a6f966a760ea900ec052436f7696cfd22
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tomcat@sha256:44c7b7b20e4777bf147ea30075489916f6deb97cf2a78b4b0ae533ac883bf058
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tomcat@sha256:c5727e40d1ab8d414d214380563799f72b23be0fc4a3eeab3fdc90460e57e297
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tomcat@sha256:09334cdef210b78f2b6d07cc3fbcf014a759cb08a1cdfb8bc336c9f76a968d41
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tomcat@sha256:5d88853b7a076d7741420ab7a9484ee81b0b0f86ba76730b350c516fd70ca1fd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tomcat@sha256:cf27633cdb6fb5d277bdf2fead4d75b128bbc9a3e35dcd09035d2ca846c58f08
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tomcat@sha256:edff0f59e7c0693ce0e7ba9e8220b9a725695c65463a20d1b3beacdb30c44c98
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tomcat@sha256:5be94f9c9e1f7a3b4e47cbbfb6221587cac24206895187ab54fcfab7bd5203f9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tomcat@sha256:237f2704e55910150c90b34073d56761ea828833da3f80279838e4883b0d21ac
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tomcat@sha256:e5fcd705f74d27a4761a40d98b5aa6adef5bfb5f5393d167e9114e2237f65e8f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tomcat@sha256:b992fbd25feee5aa060263d30d0672ce17c1108fc9dd40d1c10925c6eed6dbed
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tomcat@sha256:17f26e6618d8f7e3e818335179164233f50fa10bc6394df3ed68d90cf92baa40
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tomcat@sha256:72904414d59374d2ba659201e3f73d41a7b01fc0622bb5d98685adfed5ee0580