Sign inSign up
Tomcat

dhi.io/tomcat

Tomcat 9.x JDK 21.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

9-jdk21-debian-fips-dev, 9-jdk21-debian13-fips-dev, 9-jdk21-fips-dev, 9.0-jdk21-debian-fips-dev, 9.0-jdk21-debian13-fips-dev, 9.0-jdk21-fips-dev, 9.0.122-jdk21-debian-fips-dev, 9.0.122-jdk21-debian13-fips-dev, 9.0.122-jdk21-fips-dev

Index digest:

sha256:b7446b620e4da1513076e0d3a48eff02f7d8c631027339a9239acfc08c1853f7

Manifest digest:

sha256:0e43d5aed82c356a055c2bf2e11e09cb348fdac9ea154faaa27ff5aafc6b5377

Size

183.56 MB

Last pushed

1 day ago

Vulnerabilities

0
2
0
13
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tomcat:9-jdk21-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tomcat:9-jdk21-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tomcat@sha256:8548a99c0bb407d47b7c34beb210af30d3a2d002e2afa26456a4028ac700c44b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tomcat@sha256:479e06db265790f2a57bcfd877b147b32a8d97d9fd5d461a7007523830974990
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tomcat@sha256:562b0ef618f5d3d1449e1b9ce6b9c5c8614a01df3b9cd0730d907e06eac84b88
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tomcat@sha256:abba021fb0bc30d0fed5147954afe7bc123365eef02df74d91f58112c863adc3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tomcat@sha256:402fb297136ec519b49b9a3aadf7f46db4d62cfb3caa2354d760af7974abc6c6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tomcat@sha256:9fc2c57fd15e7a02b3531a9fb4baee5f84ba3d905829c57509b72ae284b0fded
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tomcat@sha256:e6775f976677f66b23bfdfe3d77e56343ec95539710f8d33cb4d2683a8a68d10
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tomcat@sha256:fab08c900e2b95d0354cbc6c67ff536bda974363ddb59b308db6966483fa2e0f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tomcat@sha256:f2c348626f6fcc11d813e6096a3595f4c7d3efeea85cd7b2fa525b9b12f5d4ed
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tomcat@sha256:4c09178d0cc421ece06086c68f5c3e14077c30402a68aa0be89e861bd7b1d1cc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tomcat@sha256:8fed8217be4101826cce8ccb3587c3b6626f1d1bef780b8a41b9e232c1369b49
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tomcat@sha256:b24b8e113225e91f85906b9386805af11f15051d4947b25c28e9e07054c8ded5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tomcat@sha256:000c179dd4f8bc559e079f6aa9be30b3b2e64d6093e4d91e627cddcc158d06de
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tomcat@sha256:14d40158129354b62b5fef74f54cb0f8b41696a7e4641be0b80acea50fbd9abb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tomcat@sha256:f5c6384a9c86c7d2f8de77cf842117013d03322ff111be81a571303acef22f8a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tomcat@sha256:f6cbe9bf1881cd8f9d97e1c93e50099c7f8e40d0e0981f1fffaf9afccf7acde0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tomcat@sha256:482851dc4fc514fe600ddbb0ce4406e0351fe296fc3f02b9592ccf3e67614ab5