dhi.io/tomcat
9-jdk21-debian-fips-dev, 9-jdk21-debian13-fips-dev, 9-jdk21-fips-dev, 9.0-jdk21-debian-fips-dev, 9.0-jdk21-debian13-fips-dev, 9.0-jdk21-fips-dev, 9.0.122-jdk21-debian-fips-dev, 9.0.122-jdk21-debian13-fips-dev, 9.0.122-jdk21-fips-dev
sha256:b7446b620e4da1513076e0d3a48eff02f7d8c631027339a9239acfc08c1853f7
Manifest digest:sha256:0e43d5aed82c356a055c2bf2e11e09cb348fdac9ea154faaa27ff5aafc6b5377
Size
183.56 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tomcat:9-jdk21-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tomcat:9-jdk21-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tomcat@sha256:8548a99c0bb407d47b7c34beb210af30d3a2d002e2afa26456a4028ac700c44b |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tomcat@sha256:479e06db265790f2a57bcfd877b147b32a8d97d9fd5d461a7007523830974990 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/tomcat@sha256:562b0ef618f5d3d1449e1b9ce6b9c5c8614a01df3b9cd0730d907e06eac84b88 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tomcat@sha256:abba021fb0bc30d0fed5147954afe7bc123365eef02df74d91f58112c863adc3 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/tomcat@sha256:402fb297136ec519b49b9a3aadf7f46db4d62cfb3caa2354d760af7974abc6c6 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tomcat@sha256:9fc2c57fd15e7a02b3531a9fb4baee5f84ba3d905829c57509b72ae284b0fded |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/tomcat@sha256:e6775f976677f66b23bfdfe3d77e56343ec95539710f8d33cb4d2683a8a68d10 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tomcat@sha256:fab08c900e2b95d0354cbc6c67ff536bda974363ddb59b308db6966483fa2e0f |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tomcat@sha256:f2c348626f6fcc11d813e6096a3595f4c7d3efeea85cd7b2fa525b9b12f5d4ed |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tomcat@sha256:4c09178d0cc421ece06086c68f5c3e14077c30402a68aa0be89e861bd7b1d1cc |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tomcat@sha256:8fed8217be4101826cce8ccb3587c3b6626f1d1bef780b8a41b9e232c1369b49 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tomcat@sha256:b24b8e113225e91f85906b9386805af11f15051d4947b25c28e9e07054c8ded5 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tomcat@sha256:000c179dd4f8bc559e079f6aa9be30b3b2e64d6093e4d91e627cddcc158d06de |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tomcat@sha256:14d40158129354b62b5fef74f54cb0f8b41696a7e4641be0b80acea50fbd9abb |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tomcat@sha256:f5c6384a9c86c7d2f8de77cf842117013d03322ff111be81a571303acef22f8a |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tomcat@sha256:f6cbe9bf1881cd8f9d97e1c93e50099c7f8e40d0e0981f1fffaf9afccf7acde0 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tomcat@sha256:482851dc4fc514fe600ddbb0ce4406e0351fe296fc3f02b9592ccf3e67614ab5 |