Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 17.x JDK (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

17-jdk-debian-fips-dev, 17-jdk-debian13-fips-dev, 17-jdk-fips-dev, 17.0-jdk-debian-fips-dev, 17.0-jdk-debian13-fips-dev, 17.0-jdk-fips-dev, 17.0.20-jdk-debian-fips-dev, 17.0.20-jdk-debian13-fips-dev, 17.0.20-jdk-fips-dev

Index digest:

sha256:a889a08067811459ce7b674a26eab2e2a02717b87ef47707a08f318941dcf3da

Manifest digest:

sha256:b3459e0bf0dec77c656dbf8389ea5bb31917cab25d4bf3344a92bb00678ea6e5

Size

160.58 MB

Last pushed

2 hours ago

Vulnerabilities

0
2
0
13
0

Support

Ends Sep 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:17-jdk-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:17-jdk-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:a10f3cd53a55e6464f3830a15ccc10b24fa11c7cb7c70f8c0be957a9b1b8d820
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:43bbeb3a4c384467e8bdfecc938607b7f06bf53c45b2096504c275e7d94b2fb6
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:9b8bef335e699f38c5f28979a1215e8dc3c2dc0372ad9395c1af3d1cbadd9659
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:b29e7b723e9fc4ec6f88a1525797555e5a50cde6650b2603a0713879831b354e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:a2a33edc9c0788eb86fa5aa2e26f0e48c50b9f5226d2c734dd4fa2557f2d8c90
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:8ffdf01501285296db703fa8095cce72818a07a1ad229983104f279f1a8d42e0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:6e8f803bb52ccb4301bd199b8ff6b342639b0f784d288a7a37ca6bbabaa62c36
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:9bad40055a7eed0ec098b6ff9cced97045f854fd3c2f1896f1e3d4221029180b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:c1160c7d2e3e6f8c1fe9c44e9f5bf21007374af3af9aceeafda7478b7de9efca
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:2acc94ce751b88cf6ea0e42f3b9fc10e82dd65673f3bf3c8b11b908f7cf1cbfa
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:d0452a25bc338dc2c6d6c5640a035c4598ba1d0882246c073109f88419e3e533
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:b9b502d2e7082b1f7150977123b627449a7ff0862fae288528dde28d994c14b3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:c94a1ad37b5b8f4a5f34f830aff055ca7b9d2d8f1b88f961be20c85b97d2d1ea
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:0661515cf2a5c4d93b2c368878158cab79337276c65cd0064126c08de594d41b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:8fb75ec64780da6c48acd0ec6bdb10ce962f692a6441de135624e4fab8ea3308
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:3260167f8cf735aca26f2eb78bb35c6290049fe540d5de650ab729e7143c300b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:96b50b8b0bbb855a7b4b4955e500103e641b3f61abd05d2ae263b5c33126a424