dhi.io/tomcat
10-jdk21-debian-fips-dev, 10-jdk21-debian13-fips-dev, 10-jdk21-fips-dev, 10.1-jdk21-debian-fips-dev, 10.1-jdk21-debian13-fips-dev, 10.1-jdk21-fips-dev, 10.1.59-jdk21-debian-fips-dev, 10.1.59-jdk21-debian13-fips-dev, 10.1.59-jdk21-fips-dev
sha256:11c178eb4fd01ea880a3e186ef93f36195428b2816b655832fc598b874418e51
Manifest digest:sha256:f44654adc7d3968c7ea48ef7e26cb6b3be4031effdb4811555aaaff6660876cb
Size
187.66 MB
Last pushed
4 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tomcat:10-jdk21-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tomcat:10-jdk21-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tomcat@sha256:c0f518c193f2adca97530952c5c3331fb5593c2c623cbe740e781af60a95b502 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tomcat@sha256:5bdd3f3466ce9ec0284f3c75833946fbcdbee1c6c3a0f15d3c65fe36e92f31ae |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/tomcat@sha256:3df225e8bb40b5d6bb54fd6aa58be630d7d3240b41df2e4c3d09245a02748be1 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tomcat@sha256:f5a77afc1a6f0a2fa9db2c1b0270d4a13e0c8f366ab706f570f708f1d31359b1 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/tomcat@sha256:0c73c182eade17eb732f75f98f9a0a8188a117c7b1122035c64e2dad0d01b43c |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tomcat@sha256:5d7b0c62ec46680cc2fe85caba49d6fbc32f9549d771d0df7914cfb45b654185 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/tomcat@sha256:e223f4f061dfcf8c43a949bc570b7d4fde2699753b68be38c1df4151b1b809e9 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tomcat@sha256:6f3f298d7c6c42e99eadfd767b68c9c7ef9cae080fcb940d2a21af785f0e18b6 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tomcat@sha256:1e3f5dce8f76517e5dc7a917682730e5e201bb02b54950bbdd72631a46cfa400 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tomcat@sha256:d76c0743c5dc8de71b3a911d5d2abed182f45bd527e8434b48ba9392004f620d |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tomcat@sha256:be333c38f38ce39ea64d78da55078f3542831de90f1d9cb8f52a01b08860e236 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tomcat@sha256:59472f4001a0bdee9c75bfadfa8ea6e35961da91b3f3078c5481819e8055876b |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tomcat@sha256:2a227a3f09fd3590d6cc1dee8c383e54ddb49c7ae1605fe822f2f19b0e24496b |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tomcat@sha256:d6e35c5452a2a3b6730fa59672b891a583a04e66745c07a5bcd3cc9d9c3de2fe |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tomcat@sha256:30f4f83e68ad2b5ba9e72b35be2d361874390c79fd5f620056c61174559c453f |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tomcat@sha256:58592a868f2dc81e17d6ac025d0bbf553ffe35380fcb155e5fb253758654acea |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tomcat@sha256:3bc7e5619778c297caffeb937b54a037d0e3941dbb7d81c3fea87ecf1a3fcbc0 |