Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 17.x JDK (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

17-jdk-debian-fips-dev, 17-jdk-debian13-fips-dev, 17-jdk-fips-dev, 17.0-jdk-debian-fips-dev, 17.0-jdk-debian13-fips-dev, 17.0-jdk-fips-dev, 17.0.20-jdk-debian-fips-dev, 17.0.20-jdk-debian13-fips-dev, 17.0.20-jdk-fips-dev

Index digest:

sha256:e00936e9444a38ed4711a86945c19a7f426dcea67444ff2d166e291ccd3f1649

Manifest digest:

sha256:e9cd512af40ec5389b65298f0253a33a267269068b01a07d179c5c7b3fbd7e77

Size

166.63 MB

Last pushed

4 hours ago

Vulnerabilities

1
2
0
14
0

Support

Ends Sep 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:17-jdk-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:17-jdk-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:d8c649a6a17018173d570791895c0c23a6d8ffbcef112aeb5dbc76410934a82b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:2d772d27435ff8a4f0865f5812c01fda4a8f462ae8b72b0a0621f2a0f771a730
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:0732f56b922998e8f41f6f444d32df94305b041a3ce5f45173e79d916930ebd1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:d2efc67f4ad788e30fbdf0dab81b32c236b7bc06488f36e755d71f6769d56bb4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:d076c2cbc8777558bdd48c99c468bb5025b4f50f76e02251d1ff8555c08f24c7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:9b516cffed02bfbc6ca53bc2c6bf413a64c25c7811c3673ef806f71628ee4644
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:7235b5dcc2e30ca09f456dcfff988f93470a66e3c009cf2ee5bdeb425843e1c9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:84016b6b3174b9876f9e99049493369d1922c0c9b01bc3eac6f9455d1c30b034
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:7a606b6cc022ffba160193f89c43f3b7f41f48661a2ea90882339804357044c6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:0ed13202a016ddca4b88880e7c5618c005056d2495c43994d0887a61ab30eab1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:bc3e2896a0a6f9f22479aefc106178b2f6417c648e306657e838ed7bb0cda260
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:285b97f9724197928b22a8ecfe292f0bbdf49193b4e6d3e87a40407631c50133
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:968b6c5dbce2911d76fc0fe1c6840886c526f679fe0e7c3ed0e3259ba6c0d931
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:7b54df4a67beae7b727aa9e4c49eaa8caa6d30e5d0e20b94ecb44f4aed207ccf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:3451a1d3d95a4f524a8e8573ebed26d3481be63a07fdc4b1c796bdc3d6f014fb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:09142da09913ac884e782db9d6d9e8ec1b2d54f0c4d8346c901de90ec7174283
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:5c5de7cccded92ad9a56872c4d34281420a4aee1248573f33192d3c542fe38fd