dhi.io/tomcat
11-jdk21-debian-fips-dev, 11-jdk21-debian13-fips-dev, 11-jdk21-fips-dev, 11.0-jdk21-debian-fips-dev, 11.0-jdk21-debian13-fips-dev, 11.0-jdk21-fips-dev, 11.0.26-jdk21-debian-fips-dev, 11.0.26-jdk21-debian13-fips-dev, 11.0.26-jdk21-fips-dev
sha256:fa500e31c597416a3199a7755699df855c4ab28375315f127abf22ddb64740e7
Manifest digest:sha256:fc541cd7e36ec3acedec471eb3fcfb186d7f8db16b332d120d0ce23d12f4e48c
Size
184.56 MB
Last pushed
6 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tomcat:11-jdk21-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tomcat:11-jdk21-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tomcat@sha256:203da26ae9ce581b5045ab5f7130235af73bffbbc92f426eab10c5f11bed5d01 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tomcat@sha256:3f4b3a13a521a841542e6095b965fd80b3dabf0a9ea1ea60f07c194804b87e42 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/tomcat@sha256:ee6ddd60b2adca39e20029d3e5347e50e649e3257e0bdb429b835fe0acf9f0f6 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tomcat@sha256:882c27ed5d13b62cd32856e6436243c0b5f53dcf5febfee999d4485faf8a4411 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/tomcat@sha256:75b85f901b363516ae5e74088e19aae07bff76c948ab4431065dc03392b7aa33 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tomcat@sha256:fdc9d92b9d7c38f8bbcc9eda6d1804a0c632b42d7f6621ad2293b88c1f2d6d70 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/tomcat@sha256:49673758d0fdc47f36d61e2c38593f4930e3c307dd8e53d01d49d7425a413893 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tomcat@sha256:1ef48b7602769b6e0f5b3936dae6458511f81f1299d505323083a3f921d4176e |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tomcat@sha256:3bdbdf2727e50d13bbea0255bce66d037af15b0df60d1dd324039620a16f6218 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tomcat@sha256:9fa87ed8b72ae44a43f183759fe204ce283c474053cd194683adec92b247ba53 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tomcat@sha256:c8e6d9b68faf27d9d0d6472b44ddc07babbaca64136648c05cabf7c3cb26ef74 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tomcat@sha256:0d1453661d8ca6706b6d2a5f91e10d965d680ebaf1c5c15c27133a232656178c |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tomcat@sha256:0b89456f9dd133ae457c255749ad96add9486412b77046de09c4e9bbcce0da37 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tomcat@sha256:2bcb8a06bc2a2b79fe860e24d748dda839604f591bbd51c80c41082ac62bb336 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tomcat@sha256:ca3c5fdf89219ced61650ea097e64e871170cd957ecd5a90ec42f3460ae67bd6 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tomcat@sha256:797f5a5ecdc41aa11194e03cad8771ce96933ae39821c91eeb4619cf113241f4 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tomcat@sha256:e9a48ae6e1f5bb36b5359b253b153ba5a2b8464899164999e403a92eaf9c4b9e |