dhi.io/sapmachine
17-jdk-debian-fips-dev, 17-jdk-debian13-fips-dev, 17-jdk-fips-dev, 17.0-jdk-debian-fips-dev, 17.0-jdk-debian13-fips-dev, 17.0-jdk-fips-dev, 17.0.20-jdk-debian-fips-dev, 17.0.20-jdk-debian13-fips-dev, 17.0.20-jdk-fips-dev
sha256:a889a08067811459ce7b674a26eab2e2a02717b87ef47707a08f318941dcf3da
Manifest digest:sha256:b3459e0bf0dec77c656dbf8389ea5bb31917cab25d4bf3344a92bb00678ea6e5
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/sapmachine:17-jdk-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/sapmachine:17-jdk-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/sapmachine@sha256:a10f3cd53a55e6464f3830a15ccc10b24fa11c7cb7c70f8c0be957a9b1b8d820 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/sapmachine@sha256:43bbeb3a4c384467e8bdfecc938607b7f06bf53c45b2096504c275e7d94b2fb6 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/sapmachine@sha256:9b8bef335e699f38c5f28979a1215e8dc3c2dc0372ad9395c1af3d1cbadd9659 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/sapmachine@sha256:b29e7b723e9fc4ec6f88a1525797555e5a50cde6650b2603a0713879831b354e |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/sapmachine@sha256:a2a33edc9c0788eb86fa5aa2e26f0e48c50b9f5226d2c734dd4fa2557f2d8c90 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/sapmachine@sha256:8ffdf01501285296db703fa8095cce72818a07a1ad229983104f279f1a8d42e0 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/sapmachine@sha256:6e8f803bb52ccb4301bd199b8ff6b342639b0f784d288a7a37ca6bbabaa62c36 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/sapmachine@sha256:9bad40055a7eed0ec098b6ff9cced97045f854fd3c2f1896f1e3d4221029180b |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/sapmachine@sha256:c1160c7d2e3e6f8c1fe9c44e9f5bf21007374af3af9aceeafda7478b7de9efca |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/sapmachine@sha256:2acc94ce751b88cf6ea0e42f3b9fc10e82dd65673f3bf3c8b11b908f7cf1cbfa |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/sapmachine@sha256:d0452a25bc338dc2c6d6c5640a035c4598ba1d0882246c073109f88419e3e533 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/sapmachine@sha256:b9b502d2e7082b1f7150977123b627449a7ff0862fae288528dde28d994c14b3 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/sapmachine@sha256:c94a1ad37b5b8f4a5f34f830aff055ca7b9d2d8f1b88f961be20c85b97d2d1ea |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/sapmachine@sha256:0661515cf2a5c4d93b2c368878158cab79337276c65cd0064126c08de594d41b |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/sapmachine@sha256:8fb75ec64780da6c48acd0ec6bdb10ce962f692a6441de135624e4fab8ea3308 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/sapmachine@sha256:3260167f8cf735aca26f2eb78bb35c6290049fe540d5de650ab729e7143c300b |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/sapmachine@sha256:96b50b8b0bbb855a7b4b4955e500103e641b3f61abd05d2ae263b5c33126a424 |