Sign inSign up
Tomcat

dhi.io/tomcat

Tomcat 10.x JDK 17.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

10-jdk17-debian-fips-dev, 10-jdk17-debian13-fips-dev, 10-jdk17-fips-dev, 10.1-jdk17-debian-fips-dev, 10.1-jdk17-debian13-fips-dev, 10.1-jdk17-fips-dev, 10.1.60-jdk17-debian-fips-dev, 10.1.60-jdk17-debian13-fips-dev, 10.1.60-jdk17-fips-dev

Index digest:

sha256:6fc923c4b9896d42ce390b20a9c0d61c69d29d6a662fbcf2a29f69feabe95a36

Manifest digest:

sha256:fc6d5adfdd41e0a3911f75a77a26933dff9885a116a72b399fe9e51e53be9ded

Size

178.56 MB

Last pushed

16 hours ago

Vulnerabilities

1
3
0
13
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tomcat:10-jdk17-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tomcat:10-jdk17-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tomcat@sha256:8f71d4827b59f2557c3dfbbf706466483d2e22fc642cf2c3d30cf9472fb2bfa8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tomcat@sha256:c7cb506b497f9189dece7a6c5e5c75efe5326b394b8fec6d17547b3e9c999e75
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tomcat@sha256:50e44da15aef8a8cdc0fe2a01243dd1146db75b7302020da217b86ce610fd109
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tomcat@sha256:5b7a542972ea24823ecc7d988f24ee72a3d05d55c320f8ce6e4c66b407337165
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tomcat@sha256:3d2ce62d1ededbe946f6977f877a6353b5652a7cc0326d0fc87457fc737c1516
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tomcat@sha256:99391526c4e5c9a52574c65a072df4160b0c1009509e73d457e64bae787cd0d0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tomcat@sha256:b0e966593fff0825f854be15362cbdd592b4c0c6bad20f7ee8838070244201dd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tomcat@sha256:20590e94bb1cb014fcfb7c36735407dff332c83a117bfa0f6abfd758a3a77870
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tomcat@sha256:a87981dd293fbc861ae23c2eaafcd1abf442e99ce62c4593d8d6a4907d4445a8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tomcat@sha256:632b68d5012b65b3ef05761ad23f1fc269fde68de8da9d2a6be197e858e83fe6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tomcat@sha256:b65d514f33ce14ff96cd5dd1bf39db04e6fb991d803cb861d15dbad4f9c829c0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tomcat@sha256:8e9113830c3f2b1dff2b19ce216db9d657a72d8bfe66a5431785288564d5e899
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tomcat@sha256:59cac83921ce0c823aa8bda2e5a3013b488769087f6c02f864d73e90546fe5fc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tomcat@sha256:602e659071c696412690b497f596046fb8ab5497b551990fac9ebe8355f2f567
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tomcat@sha256:ad4ea334e31b1be3fc7bafc3b7991ff546e32cb7ae2300f12edbf50040e4b2ed
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tomcat@sha256:e992478c33c36b476b88a85b42f0d2dabba46d4af655b24affa2f3e2372b4d79
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tomcat@sha256:cff820c68a0d2097a58b60c92547ae6efe84e1a7eec1647ce0fd39fd1f50e019