dhi.io/tomcat
11-jdk21-debian-fips, 11-jdk21-debian13-fips, 11-jdk21-fips, 11.0-jdk21-debian-fips, 11.0-jdk21-debian13-fips, 11.0-jdk21-fips, 11.0.26-jdk21-debian-fips, 11.0.26-jdk21-debian13-fips, 11.0.26-jdk21-fips
sha256:4aa4190fee33f034e7366da737e4d56bb454470867a6f343190e23d4bdd6e3ec
Manifest digest:sha256:c178ae5c998997eb3a714b10fb02b520313d8cfe8ad66c8b953240bf2d4cf723
Size
81.83 MB
Last pushed
3 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tomcat:11-jdk21-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tomcat:11-jdk21-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tomcat@sha256:982c200d6c3900d72bc89ea7ce6e0bf90c2b92fd32759ff253e58f4874db6672 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tomcat@sha256:ddae53dc00f44d9b6e2d3198a5c2ddd20079624611db39f46bad61f0c434f206 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/tomcat@sha256:143996a14437f6002cd04f7fd9567eb912db8be3be9dcdfbebf8f9c5b94c9fa7 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tomcat@sha256:fb089048d0e3cd872c21de620032abc1e370ec6a45329e6a3077f39d97e1a06a |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/tomcat@sha256:17e1199643d39928b97adb772ccb98b974ae07ae55ad5d1c1d6748e28687a59c |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tomcat@sha256:9a9215dfe57c7f4c68fbddacb8e8a8f936564dc74364eb83ab0a1ad02c53b0b9 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/tomcat@sha256:a2669c403bd84407da392912ce96ed475d0652e2ce35f5481446cd2c4ef7684f |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tomcat@sha256:928e025f297729a71a40213b761f193e62ff50ba526ae25b700c090be69760e9 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tomcat@sha256:b217bce30c1f04c82f042bf39c93abc143e2296af458f8240ff8e1cc6f0c8d07 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tomcat@sha256:915603995fcd334e725b29fc8f72c701da572f9ea6abc2fd8a269e4e33bf8622 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tomcat@sha256:e42a3ec93a00f334420e067abd7e786c0580e895c8d595f1733ac615b2ed0f6c |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tomcat@sha256:a89fe7b717218035098c2505ebb1a8c019f3a8a4fc28063ff1c65d5b4f6f099f |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tomcat@sha256:77f083e4ce01f8f4892542acbff8b6a8d63a6808e913138f95eb14c781708b07 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tomcat@sha256:00244b77df03eb164b7b9fa5294e182debbc1e8ae818754034bc1ae0aa76d048 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tomcat@sha256:93274aabbfbcd10281408b9c907d717b32a0c3a6e8da594ca25d1eac739084fc |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tomcat@sha256:663d39b4cf4cdd30ba9dbd2107903505b6811e8117d7893e4b16aee2811cc066 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tomcat@sha256:070bfed10d95dec97bc00803c0f9addfdca0bc5f5721839c5397d5190b91e8b0 |