dhi.io/tomcat
10-jdk25-debian-fips, 10-jdk25-debian13-fips, 10-jdk25-fips, 10.1-jdk25-debian-fips, 10.1-jdk25-debian13-fips, 10.1-jdk25-fips, 10.1.60-jdk25-debian-fips, 10.1.60-jdk25-debian13-fips, 10.1.60-jdk25-fips
sha256:028ddf7d662d84d9b2b104cdf4c8d31ffe7fa8f1ac81c086cdf19a02a215800d
Manifest digest:sha256:a7c09de52267d826bc889e19d8db872215776c071578a5ba53d4ce4b456b98b1
Size
90.16 MB
Last pushed
8 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tomcat:10-jdk25-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tomcat:10-jdk25-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tomcat@sha256:daa49c506e1703a3d93349045e6f6eb671e1a9baedd9f3353905c7024d96409d |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tomcat@sha256:5de3b6ecc47dded8d6bcffb40def07ceccc4f4f16823f626a30b96bceab09100 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/tomcat@sha256:4e3d21b0b058f0b4dbb00a923c0a9791edbc1e1c9afe2911805a8272c39b592e |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tomcat@sha256:56457f2700fce7e8ef28003426b16948f7062a45d1ef9673f26a22876c2fbc23 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/tomcat@sha256:cab7a73ba49a552c5849bcce88ac475ce9fcb14f2c3ec3ca0b85ea2027b2a154 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tomcat@sha256:296f1467ddc40880a01871947af02a0b6a5f835d0fe5fd4a1801ccc9c9a06e6e |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/tomcat@sha256:881b60077e1a1842089525ff4f871da175bd5a88fc2aa310c89020a6f1fb0684 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tomcat@sha256:b9e99b0966d3f3304b8a0df2cae0d5d64ae5cd0350535d79bb37f60274189fd6 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tomcat@sha256:bc979e797845e84caebcd8e2724bd7cc1a1379bd0ad686d7f905737f8afd0730 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tomcat@sha256:da40a44681b57ddf5c10256121fc5f7dd4c52b83ad4d774fc08a4a593ae54bdf |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tomcat@sha256:c7b4358541962dc22feb2a6479b6e615320bda8b1f332d19f983417e7e929cda |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tomcat@sha256:f8c79273fdc34bfb0c43ea32e301f49bb3f5465ae8650f308e8c41ebd45a8923 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tomcat@sha256:4fdf8561345c59d7a6d5a9fb96116d61a92da6a6a39016c00fa19c2b1c2526b9 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tomcat@sha256:21e0775ef922a9a96d230b2b022497968730aeef3753f990b89a06cfea795b57 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tomcat@sha256:930cc404d102cd4da9c9b7ca2d06503f5bf3eab448faeccc240ebae223991de4 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tomcat@sha256:55823bab3e6d9834ae640f1588f342bbff0f12498337738d048873f2a26c05dc |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tomcat@sha256:920ffac4540cec28111738780f42d152ae56dfdf2ec1181fdb810a0cbc0050e3 |