Sign inSign up
Tomcat

dhi.io/tomcat

Tomcat 11.x JDK 25.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

11-jdk25-debian-fips-dev, 11-jdk25-debian13-fips-dev, 11-jdk25-fips-dev, 11.0-jdk25-debian-fips-dev, 11.0-jdk25-debian13-fips-dev, 11.0-jdk25-fips-dev, 11.0.26-jdk25-debian-fips-dev, 11.0.26-jdk25-debian13-fips-dev, 11.0.26-jdk25-fips-dev

Index digest:

sha256:b94c68cffde95b812fabf449eafdafa756cfc4d29b63ed558b9b58c4661be5bb

Manifest digest:

sha256:cef63fa97b38664c22b352b3f6efb0cdec3776ec3712b9e4f5f71604be48aa1e

Size

123.02 MB

Last pushed

17 hours ago

Vulnerabilities

0
2
1
14
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tomcat:11-jdk25-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tomcat:11-jdk25-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tomcat@sha256:ad487020f13448f8a874128bc48981b82e5e9fe40636db352580656ea251df85
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tomcat@sha256:eb9af889f97048f155f448a075189c207a5144686cbfecdd3c3a8bd9898c9fbf
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tomcat@sha256:fc44d2b6cd8e5cec88ea15f4bc7b34e3b1e78d1f048519f51a6b395a86c9a469
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tomcat@sha256:d61d522fad32c6e85137e07371602c649d0da9a5db32213191891f5d70635221
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tomcat@sha256:57e662dc0c4e048874448f5d806835bde38a47121ee9cabb623fa222dbc6085f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tomcat@sha256:6906d90f61221cc4cc04bf543ac67b7294b1acd59e502f0d5648c05414cb990e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tomcat@sha256:7e965cf79bb7e1bc08e3ce2adf96b959dd2e3de06a25d5157a23112f0ce8e2f3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tomcat@sha256:b175896509a2f9e3c35d7f6fcf58e8145109d15030a5a6a840e5c1db5af4b743
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tomcat@sha256:df75d2ca251fa76664fab70b65f87d9fbbcf9e44cb3e6dec362db8556cceefb2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tomcat@sha256:e748f14764ded861d4e352a7cea33df2031440cf44925360bf4c683ed4d1a2ad
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tomcat@sha256:43e4931ba037db99eae1371ce39f2b6fa707026cc7e54cf283ee88b121932bf4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tomcat@sha256:869f3f5eea72b2bb5c1eeadb6bbfcd34befe09e9ac564349988b5290273c41bf
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tomcat@sha256:0fa5ca400a649c9779e50d74911cc0b5fe1cc6bc75538828a0ee268fb4611045
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tomcat@sha256:0307a67a123e4ca7f4987bdc2f9759892f6191cd3f014a423595ebc58e304910
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tomcat@sha256:b3c412b94244afcd074aa89387a007b6dabf692b5fa331abd0562bec44c4bf0f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tomcat@sha256:fc4e5c4c1563b0f4a23f224e42dd390bb153d99e97f3070631ba1d7bf912d5ed
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tomcat@sha256:13fd04e341625f5439a95128b29bc29f718ca0b65f412c962525b0835dbc3012