Sign inSign up
Tomcat

dhi.io/tomcat

Tomcat 11.x JDK 21.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

11-jdk21-debian-fips-dev, 11-jdk21-debian13-fips-dev, 11-jdk21-fips-dev, 11.0-jdk21-debian-fips-dev, 11.0-jdk21-debian13-fips-dev, 11.0-jdk21-fips-dev, 11.0.26-jdk21-debian-fips-dev, 11.0.26-jdk21-debian13-fips-dev, 11.0.26-jdk21-fips-dev

Index digest:

sha256:fa500e31c597416a3199a7755699df855c4ab28375315f127abf22ddb64740e7

Manifest digest:

sha256:fc541cd7e36ec3acedec471eb3fcfb186d7f8db16b332d120d0ce23d12f4e48c

Size

184.56 MB

Last pushed

6 days ago

Vulnerabilities

0
3
0
13
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tomcat:11-jdk21-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tomcat:11-jdk21-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tomcat@sha256:203da26ae9ce581b5045ab5f7130235af73bffbbc92f426eab10c5f11bed5d01
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tomcat@sha256:3f4b3a13a521a841542e6095b965fd80b3dabf0a9ea1ea60f07c194804b87e42
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tomcat@sha256:ee6ddd60b2adca39e20029d3e5347e50e649e3257e0bdb429b835fe0acf9f0f6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tomcat@sha256:882c27ed5d13b62cd32856e6436243c0b5f53dcf5febfee999d4485faf8a4411
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tomcat@sha256:75b85f901b363516ae5e74088e19aae07bff76c948ab4431065dc03392b7aa33
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tomcat@sha256:fdc9d92b9d7c38f8bbcc9eda6d1804a0c632b42d7f6621ad2293b88c1f2d6d70
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tomcat@sha256:49673758d0fdc47f36d61e2c38593f4930e3c307dd8e53d01d49d7425a413893
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tomcat@sha256:1ef48b7602769b6e0f5b3936dae6458511f81f1299d505323083a3f921d4176e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tomcat@sha256:3bdbdf2727e50d13bbea0255bce66d037af15b0df60d1dd324039620a16f6218
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tomcat@sha256:9fa87ed8b72ae44a43f183759fe204ce283c474053cd194683adec92b247ba53
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tomcat@sha256:c8e6d9b68faf27d9d0d6472b44ddc07babbaca64136648c05cabf7c3cb26ef74
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tomcat@sha256:0d1453661d8ca6706b6d2a5f91e10d965d680ebaf1c5c15c27133a232656178c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tomcat@sha256:0b89456f9dd133ae457c255749ad96add9486412b77046de09c4e9bbcce0da37
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tomcat@sha256:2bcb8a06bc2a2b79fe860e24d748dda839604f591bbd51c80c41082ac62bb336
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tomcat@sha256:ca3c5fdf89219ced61650ea097e64e871170cd957ecd5a90ec42f3460ae67bd6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tomcat@sha256:797f5a5ecdc41aa11194e03cad8771ce96933ae39821c91eeb4619cf113241f4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tomcat@sha256:e9a48ae6e1f5bb36b5359b253b153ba5a2b8464899164999e403a92eaf9c4b9e