Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 17.x JDK (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

17-jdk-debian-fips-dev, 17-jdk-debian13-fips-dev, 17-jdk-fips-dev, 17.0-jdk-debian-fips-dev, 17.0-jdk-debian13-fips-dev, 17.0-jdk-fips-dev, 17.0.20-jdk-debian-fips-dev, 17.0.20-jdk-debian13-fips-dev, 17.0.20-jdk-fips-dev

Index digest:

sha256:fd2502dbcf6660c27b11a1959204d43699b4fa733ae6ebd749829d69f426891d

Manifest digest:

sha256:81716af4ca7e6ccc7579b75d895cb95689e5d5893cdf1c6d2db224adba145a5c

Size

166.65 MB

Last pushed

9 hours ago

Vulnerabilities

1
2
0
14
0

Support

Ends Sep 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:17-jdk-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:17-jdk-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:60283aff55a06b16043bfc3e8cfe43e54184929a8a8ea4f598d3b5c20f8509ee
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:52795134b53fe051c507937b43d23a7001d106893f3f336d0f60ec4948adb40b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:c67c9553133458a150563187f07302f130d5c00d48f6d6c3bdd76d2dcf82e5ff
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:3e282ee7c997ae2ff6332bf8b67a71dd5ed5cc1dd5ddde706c5a2d8c27e158c0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:5ffa04427b60f34c3b7290f4cdd84480db8537750da65216005327f672027b76
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:746d62b2170acb8ecf18c49df8faa0e2e0ca14c5de64d1de299abb6129ecfb7f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:417ad1b46bafb80293bd0588eb5b0268f3a5013d756ec70e8266f3a04a0d4d4b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:47a3cb58721646882d7e49e988e84a9301f9a00b0921a03cb25fa02232b63fd6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:4b280ed192dd1515bac6cf71dd73ac771149826c7c4005822d3ba4581b2b2f7a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:026da4e7cf3ef92e56d9313f9d8bd7b898a91d22fed6ddece837e2ee38129780
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:0e8428d53cbe4b465186c52503ab6757c9b992cb009e46168409afd6eb568d89
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:cd3e625a56a15c675a83f7dfcd26a139d238192118e246945c97883d86c4d084
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:d34f50d4edc71492b4aa30d066f32858cff43fd0ad53b6f016c2029765d0ff87
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:2a174f0fd043832b8990193b42550f7d90b5b357cf9f933b7bf659f758012b90
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:9ed8ab300c5f6f6dd10f7dd23b8fe5929703779ab741c0616da74086fb6d2028
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:7ba17abf5b867385c9c2d5c897e64489554b38474b706f0473111c74a62339eb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:7f4080a7105b95dd0a6cb7db01a155ffe1f66679a7b2d6168a3ea56f7e9f044b