Sign inSign up
Tomcat

dhi.io/tomcat

Tomcat 10.x JDK 21.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

10-jdk21-debian-fips, 10-jdk21-debian13-fips, 10-jdk21-fips, 10.1-jdk21-debian-fips, 10.1-jdk21-debian13-fips, 10.1-jdk21-fips, 10.1.60-jdk21-debian-fips, 10.1.60-jdk21-debian13-fips, 10.1.60-jdk21-fips

Index digest:

sha256:dd2394aea6fecfc2195c51d4e316d1500d65d520fe71ad56e62dce2cd8f317a9

Manifest digest:

sha256:d0725e103118a0844c772e471e57b30ebfea049dd0d33cd70c097403b9c6cef1

Size

81.74 MB

Last pushed

8 hours ago

Vulnerabilities

1
2
0
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tomcat:10-jdk21-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tomcat:10-jdk21-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tomcat@sha256:3b4f8a33767192906c1cfb8c4fc7ca60b9db81efe7070c2144892295576c2f58
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tomcat@sha256:22bd2fdbcf9d6c1d9c9c4032385456f0957db3119d08c6145a3510100e3b6402
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tomcat@sha256:ae3bbe6949f10a6bb3ef4db17eec9abf4a582c46a2f2ccb7643c52281b2e4caa
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tomcat@sha256:389c813b5590575cae3258c7765f041d0c2bd8132cb23b9fbc20f35576d7a069
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tomcat@sha256:a56f9573ffd223107180b9d16f67e95cc87ab8025cbbd8197fb219205fecf46c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tomcat@sha256:ed7ea44a787a114513168041da296683f1aa88928619c0e8eceee703e688817a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tomcat@sha256:b4ed770e9152d4f271d27a2c5e3811e92a7191041f4c1c47226c3c115b713deb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tomcat@sha256:f39349ff900a815f56ba064e0564b467f1b5f6b593129adc964241a9195b49b2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tomcat@sha256:b85156e8519603578f00a839c17c9aa1570bb4bc6808599085fe2cdf38b08228
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tomcat@sha256:7aa99c855e109f14efcfe3490e2839a02aaa154257c56de9945f37ad23a0308b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tomcat@sha256:2c2e227ddec7eecedfe868434fbfb4a3e3413813bf9609312527a2fa94e4079e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tomcat@sha256:87ff1bd8674569b787cba777f3372e3669de0835d5c67df9f5e59ca1230bd2c7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tomcat@sha256:1574b7c45aff4572cd93e39109a88b4259cbdf09fa51ea068da5310f44be999c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tomcat@sha256:41b9159b78388315ef4d0e48391a07c1032747f2236b7709369285a47af7e59d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tomcat@sha256:1e72ec6d30ab60fe965304ece28419ba50bddb3e1d497f3342fb0fa210216591
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tomcat@sha256:14baa541860db516daae75d3543737c6140b6e08822ba77105bd7a1db058e078
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tomcat@sha256:f7703ad5d9c943a36086e9e4559c769bd5e26aa27f2f235d1d36850fa916b9ef