Sign inSign up
Tomcat

dhi.io/tomcat

Tomcat 11.x JDK 21.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

11-jdk21-debian-fips, 11-jdk21-debian13-fips, 11-jdk21-fips, 11.0-jdk21-debian-fips, 11.0-jdk21-debian13-fips, 11.0-jdk21-fips, 11.0.26-jdk21-debian-fips, 11.0.26-jdk21-debian13-fips, 11.0.26-jdk21-fips

Index digest:

sha256:4aa4190fee33f034e7366da737e4d56bb454470867a6f343190e23d4bdd6e3ec

Manifest digest:

sha256:c178ae5c998997eb3a714b10fb02b520313d8cfe8ad66c8b953240bf2d4cf723

Size

81.83 MB

Last pushed

3 days ago

Vulnerabilities

1
2
0
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tomcat:11-jdk21-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tomcat:11-jdk21-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tomcat@sha256:982c200d6c3900d72bc89ea7ce6e0bf90c2b92fd32759ff253e58f4874db6672
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tomcat@sha256:ddae53dc00f44d9b6e2d3198a5c2ddd20079624611db39f46bad61f0c434f206
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tomcat@sha256:143996a14437f6002cd04f7fd9567eb912db8be3be9dcdfbebf8f9c5b94c9fa7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tomcat@sha256:fb089048d0e3cd872c21de620032abc1e370ec6a45329e6a3077f39d97e1a06a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tomcat@sha256:17e1199643d39928b97adb772ccb98b974ae07ae55ad5d1c1d6748e28687a59c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tomcat@sha256:9a9215dfe57c7f4c68fbddacb8e8a8f936564dc74364eb83ab0a1ad02c53b0b9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tomcat@sha256:a2669c403bd84407da392912ce96ed475d0652e2ce35f5481446cd2c4ef7684f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tomcat@sha256:928e025f297729a71a40213b761f193e62ff50ba526ae25b700c090be69760e9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tomcat@sha256:b217bce30c1f04c82f042bf39c93abc143e2296af458f8240ff8e1cc6f0c8d07
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tomcat@sha256:915603995fcd334e725b29fc8f72c701da572f9ea6abc2fd8a269e4e33bf8622
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tomcat@sha256:e42a3ec93a00f334420e067abd7e786c0580e895c8d595f1733ac615b2ed0f6c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tomcat@sha256:a89fe7b717218035098c2505ebb1a8c019f3a8a4fc28063ff1c65d5b4f6f099f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tomcat@sha256:77f083e4ce01f8f4892542acbff8b6a8d63a6808e913138f95eb14c781708b07
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tomcat@sha256:00244b77df03eb164b7b9fa5294e182debbc1e8ae818754034bc1ae0aa76d048
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tomcat@sha256:93274aabbfbcd10281408b9c907d717b32a0c3a6e8da594ca25d1eac739084fc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tomcat@sha256:663d39b4cf4cdd30ba9dbd2107903505b6811e8117d7893e4b16aee2811cc066
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tomcat@sha256:070bfed10d95dec97bc00803c0f9addfdca0bc5f5721839c5397d5190b91e8b0