Sign inSign up
Tomcat

dhi.io/tomcat

Tomcat 10.x JDK 21.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

10-jdk21-debian-fips-dev, 10-jdk21-debian13-fips-dev, 10-jdk21-fips-dev, 10.1-jdk21-debian-fips-dev, 10.1-jdk21-debian13-fips-dev, 10.1-jdk21-fips-dev, 10.1.59-jdk21-debian-fips-dev, 10.1.59-jdk21-debian13-fips-dev, 10.1.59-jdk21-fips-dev

Index digest:

sha256:11c178eb4fd01ea880a3e186ef93f36195428b2816b655832fc598b874418e51

Manifest digest:

sha256:f44654adc7d3968c7ea48ef7e26cb6b3be4031effdb4811555aaaff6660876cb

Size

187.66 MB

Last pushed

4 days ago

Vulnerabilities

1
2
0
14
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tomcat:10-jdk21-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tomcat:10-jdk21-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tomcat@sha256:c0f518c193f2adca97530952c5c3331fb5593c2c623cbe740e781af60a95b502
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tomcat@sha256:5bdd3f3466ce9ec0284f3c75833946fbcdbee1c6c3a0f15d3c65fe36e92f31ae
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tomcat@sha256:3df225e8bb40b5d6bb54fd6aa58be630d7d3240b41df2e4c3d09245a02748be1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tomcat@sha256:f5a77afc1a6f0a2fa9db2c1b0270d4a13e0c8f366ab706f570f708f1d31359b1
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tomcat@sha256:0c73c182eade17eb732f75f98f9a0a8188a117c7b1122035c64e2dad0d01b43c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tomcat@sha256:5d7b0c62ec46680cc2fe85caba49d6fbc32f9549d771d0df7914cfb45b654185
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tomcat@sha256:e223f4f061dfcf8c43a949bc570b7d4fde2699753b68be38c1df4151b1b809e9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tomcat@sha256:6f3f298d7c6c42e99eadfd767b68c9c7ef9cae080fcb940d2a21af785f0e18b6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tomcat@sha256:1e3f5dce8f76517e5dc7a917682730e5e201bb02b54950bbdd72631a46cfa400
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tomcat@sha256:d76c0743c5dc8de71b3a911d5d2abed182f45bd527e8434b48ba9392004f620d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tomcat@sha256:be333c38f38ce39ea64d78da55078f3542831de90f1d9cb8f52a01b08860e236
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tomcat@sha256:59472f4001a0bdee9c75bfadfa8ea6e35961da91b3f3078c5481819e8055876b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tomcat@sha256:2a227a3f09fd3590d6cc1dee8c383e54ddb49c7ae1605fe822f2f19b0e24496b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tomcat@sha256:d6e35c5452a2a3b6730fa59672b891a583a04e66745c07a5bcd3cc9d9c3de2fe
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tomcat@sha256:30f4f83e68ad2b5ba9e72b35be2d361874390c79fd5f620056c61174559c453f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tomcat@sha256:58592a868f2dc81e17d6ac025d0bbf553ffe35380fcb155e5fb253758654acea
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tomcat@sha256:3bc7e5619778c297caffeb937b54a037d0e3941dbb7d81c3fea87ecf1a3fcbc0