Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 21.x JDK (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

21-jdk-debian-fips-dev, 21-jdk-debian13-fips-dev, 21-jdk-fips-dev, 21.0-jdk-debian-fips-dev, 21.0-jdk-debian13-fips-dev, 21.0-jdk-fips-dev, 21.0.12-jdk-debian-fips-dev, 21.0.12-jdk-debian13-fips-dev, 21.0.12-jdk-fips-dev

Index digest:

sha256:4241783df71b16a0bf95ad01f7bb582348b269c40ee9c520a8147bfa67d7f676

Manifest digest:

sha256:46d8b18449cd9f8219d9309e813b36b854d7da16a13bf0ec69e5f4fa6274a2fc

Size

176.22 MB

Last pushed

7 hours ago

Vulnerabilities

1
2
0
14
0

Support

Active until Sep 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:21-jdk-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:21-jdk-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:8856ab76101448c9ff8999745261e4b1d89723095a3c9d85890f800d6ff26434
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:c32026d5593e01e9450e5c284bbb37b13d1f58a0b452aa3609e897f0d10eaaea
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:40d8878411b77cc59d1f04408f208a91dede928b6a56e05d9141ecc7cd4833b2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:cbde69622dde09a75eb6db412efb1498a034a30f58988e8917f8f8426fc96ad2
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:31bef3e050e3939426b5545675b7eebfbce285607858c8c88ddbe6072caf3bcc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:1629913afb0dc85b7032ab73a55b07a1e0a4206d83369c69d40a3dae23b71e34
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:2c0c9ae5a1e86cabe91f73c21539466f9ea06ce1fd21c44cf15ffb464dc05a42
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:a0d3ea28d709ad6d3355ea334cf14865aaef5bfc14f21324388a279b72dd4097
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:3da8bee0d58cb214295b73a836840c199d79647216f7548d1f47303bc3d65fcb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:34c8afa650184ea2627441e353178df2e5b0b11041b633c4f18025daeaac3725
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:68291991249720f639aa87bc4d409d0064f53bdf2672e8f41c9b912dde0cdde8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:84a97b425bf7e7bc75332938b41b7e76c19e3e53123955da9f65c6387daeba41
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:29ae5d276ef46d55250598673df4d659742f17d8c57a67a64ed5204dc921d1f3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:095da48e13922e5ec1771349e11b410bcd821e417ea8a589cec7702687ff88f2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:c4a6c5fcd85b19c228417d9eda0542d636b51b71823b92cd642bb8468c84c34b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:a811b9ba8784a09a2326139b509a1d66da818579d3df2e94ca5e2bb1fdb88f1f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:f50c237171ed82de8a8bdd2c33639e6e0abd0d76572596c17818759b02ddecf2