Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 17.x JDK (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

17-jdk-debian-fips-dev, 17-jdk-debian13-fips-dev, 17-jdk-fips-dev, 17.0-jdk-debian-fips-dev, 17.0-jdk-debian13-fips-dev, 17.0-jdk-fips-dev, 17.0.20-jdk-debian-fips-dev, 17.0.20-jdk-debian13-fips-dev, 17.0.20-jdk-fips-dev

Index digest:

sha256:1d7b92075ad258fd0b5e36c2729b89515994efb6c0beebf939fb63660b5c4e11

Manifest digest:

sha256:058b80ae030266f3be2562f0424a15ef5151aa9c716b616c4a0f3c18bf7ccb2f

Size

166.63 MB

Last pushed

2 hours ago

Vulnerabilities

1
2
0
14
0

Support

Ends Sep 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:17-jdk-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:17-jdk-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:bfa99dedebe1726040304df4a2ff17df64c1ec13b69216532a1b53113e2c52f0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:99422c482e4aa686eba822910c7f264287bf3612e333dc75052f1bd3033b6042
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:80534e6f1253a7396010b89c6208fb951000d7996e19fc74ad38ce35bf0cd660
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:be736a1efdfba12053094f8dbb3a453e8752cbd6f5d75083742506eb65c96f3e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:355c18719a33356492a915d3f208bdb058b57d160086492cbdd45df7575613b5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:8e1576791fda0d75686b71d3c65bdac9ff7fdcee6668b4684a5e9492dcf60969
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:1414541f1098f58974d2e06701d743d060d83263d33c67c27bb7c90a4ceb43b1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:fc7dbc2b56801f7a56b8923f6a5ccc90f3e649b4b376d6213e6c968a3856319e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:a51e6c5a6e38b1590e44e05087e756f084cad94c0986757b3aebe67b3665199c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:03e3719a2dd0d319adafef4a3bcbb09bdb1b8464c8f904e8a7a4cb2d643e755b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:996048524faefcd96d4c7cf7fdedd1e84644d70b3edc73721e3afa89c14c47bb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:17b3a6df9557bfb28cd1d12fe447ef322f385e092e874a54397c3720724ccedb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:afff4b16df1236be17b9e33faa25be67db9f02c4b2eb9aeb0ca43c28a5bae98a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:bdbbb04ec1a08f42fb35fcf1b1df93049556b197f178576906843e608946856d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:1536f222c0ed122b7eb021a8467fadcdf47a131279e1b73aa405183a3abd66e4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:6f9eebc39286f94a982eb03e883bc088674f7ecdef98d846d4f1f75ac3e7741a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:370abfea9f968a000d75dacbf1418b38f5e66c7df55278cfcd91fae80b882029