Sign inSign up
Tomcat

dhi.io/tomcat

Tomcat 10.x JDK 21.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

10-jdk21-debian-fips-dev, 10-jdk21-debian13-fips-dev, 10-jdk21-fips-dev, 10.1-jdk21-debian-fips-dev, 10.1-jdk21-debian13-fips-dev, 10.1-jdk21-fips-dev, 10.1.60-jdk21-debian-fips-dev, 10.1.60-jdk21-debian13-fips-dev, 10.1.60-jdk21-fips-dev

Index digest:

sha256:7cc9a84812ab13fd9a21f6093b8bf8b0b12820292224fb1acc949d4501341bbd

Manifest digest:

sha256:0a09f30d155deb2781382cab54f1073f628fe74dcc3e0bd9240abde9e6c29850

Size

187.76 MB

Last pushed

7 hours ago

Vulnerabilities

1
2
0
14
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tomcat:10-jdk21-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tomcat:10-jdk21-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tomcat@sha256:bff67d5280102ab314d577d0f42ab6712d7696bb4e672bae976696ed876bf395
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tomcat@sha256:5522cbd896c72ed7355586807f305af4c664d270984bfecd134daf1af02d07bc
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tomcat@sha256:5666a40cbabe652cccdf4c2eab62f5b2ea41f28e7fa79f03b53157c6941901c9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tomcat@sha256:a1c03035534dbc07b2c6277ba7cb24647728ddac56a6186d8fc8956141638eff
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tomcat@sha256:8e02099f928a9dc3adf0760436cde82b0f5a127ed9db189879e6c7241bb41750
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tomcat@sha256:19030b36ecd2d23130ccdf0820a87af631ac0561ed801b9bba6f5d34c32cefb2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tomcat@sha256:2c5a7a2f68a548fe84259a5559064ebbd2f43b889e38e50c9aab4834877dc0fa
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tomcat@sha256:850f193d1aa4ddc8871d317fda6ecc666e7487c7bfd5e146d505eec1f630a618
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tomcat@sha256:df172518455c3431bafc4e588ed89dd4ec62789baf93c9e69ff388957bb4e4bd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tomcat@sha256:4e8d80a946e128a05b8b14c37590b70550bd1432c3a0114ba98331617e4bd5f0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tomcat@sha256:5f49865b64c941bd1583b448a75055d1b034296869d8d8e9e054837a4531ed7b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tomcat@sha256:eeb9b742c15c1799e74a02e922cc83617ef9e1ceac307ef120e4a9eb016e5be8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tomcat@sha256:cc78536ce30a6c6623e937dd03111d7f28d683e9011ff16daf830f12685ea66f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tomcat@sha256:26bb8ad067c01953e7059abbbb2e3359b409a0d4fb288c0037a9dd38e7609f97
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tomcat@sha256:56c5da046313a3552ac97f4a5d0523e524b39b983743fe0ac6698c41688b9af8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tomcat@sha256:e6af2340b83182b31b4e866778234dbbb0c5ad204d2798fef59152b191b3f355
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tomcat@sha256:bce8ca0bb0f73f0b59cd1912a80695baf514836275590c505d5f9ab8f2f9f51f