dhi.io/sapmachine
17-jdk-debian-fips-dev, 17-jdk-debian13-fips-dev, 17-jdk-fips-dev, 17.0-jdk-debian-fips-dev, 17.0-jdk-debian13-fips-dev, 17.0-jdk-fips-dev, 17.0.20-jdk-debian-fips-dev, 17.0.20-jdk-debian13-fips-dev, 17.0.20-jdk-fips-dev
sha256:fd2502dbcf6660c27b11a1959204d43699b4fa733ae6ebd749829d69f426891d
Manifest digest:sha256:81716af4ca7e6ccc7579b75d895cb95689e5d5893cdf1c6d2db224adba145a5c
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/sapmachine:17-jdk-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/sapmachine:17-jdk-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/sapmachine@sha256:60283aff55a06b16043bfc3e8cfe43e54184929a8a8ea4f598d3b5c20f8509ee |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/sapmachine@sha256:52795134b53fe051c507937b43d23a7001d106893f3f336d0f60ec4948adb40b |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/sapmachine@sha256:c67c9553133458a150563187f07302f130d5c00d48f6d6c3bdd76d2dcf82e5ff |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/sapmachine@sha256:3e282ee7c997ae2ff6332bf8b67a71dd5ed5cc1dd5ddde706c5a2d8c27e158c0 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/sapmachine@sha256:5ffa04427b60f34c3b7290f4cdd84480db8537750da65216005327f672027b76 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/sapmachine@sha256:746d62b2170acb8ecf18c49df8faa0e2e0ca14c5de64d1de299abb6129ecfb7f |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/sapmachine@sha256:417ad1b46bafb80293bd0588eb5b0268f3a5013d756ec70e8266f3a04a0d4d4b |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/sapmachine@sha256:47a3cb58721646882d7e49e988e84a9301f9a00b0921a03cb25fa02232b63fd6 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/sapmachine@sha256:4b280ed192dd1515bac6cf71dd73ac771149826c7c4005822d3ba4581b2b2f7a |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/sapmachine@sha256:026da4e7cf3ef92e56d9313f9d8bd7b898a91d22fed6ddece837e2ee38129780 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/sapmachine@sha256:0e8428d53cbe4b465186c52503ab6757c9b992cb009e46168409afd6eb568d89 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/sapmachine@sha256:cd3e625a56a15c675a83f7dfcd26a139d238192118e246945c97883d86c4d084 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/sapmachine@sha256:d34f50d4edc71492b4aa30d066f32858cff43fd0ad53b6f016c2029765d0ff87 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/sapmachine@sha256:2a174f0fd043832b8990193b42550f7d90b5b357cf9f933b7bf659f758012b90 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/sapmachine@sha256:9ed8ab300c5f6f6dd10f7dd23b8fe5929703779ab741c0616da74086fb6d2028 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/sapmachine@sha256:7ba17abf5b867385c9c2d5c897e64489554b38474b706f0473111c74a62339eb |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/sapmachine@sha256:7f4080a7105b95dd0a6cb7db01a155ffe1f66679a7b2d6168a3ea56f7e9f044b |