Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 21.x JDK (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

21-jdk-debian-fips-dev, 21-jdk-debian13-fips-dev, 21-jdk-fips-dev, 21.0-jdk-debian-fips-dev, 21.0-jdk-debian13-fips-dev, 21.0-jdk-fips-dev, 21.0.12-jdk-debian-fips-dev, 21.0.12-jdk-debian13-fips-dev, 21.0.12-jdk-fips-dev

Index digest:

sha256:4fe122c60fc2be8b06169e8ec91d2ecb90247aa6a89aee6c8a6572d5a54d82f9

Manifest digest:

sha256:640a900b78f2d9fc6c1f1a785853d9a2560ffd451ab51053f9ee09ff8b307d7a

Size

170.17 MB

Last pushed

6 hours ago

Vulnerabilities

0
2
0
13
0

Support

Active until Sep 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:21-jdk-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:21-jdk-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:7cf37b8f334992106162bb942899af04ece7a2389c562de4197a6b5c5c8474ef
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:030207776ff0f9c48dca06f38ec0e545097228c2429a239fca45536e8168dcd1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:5ad36c05e28c2bab2cbea1ea081cdf97a72cd96405624e2723e8c36f77cb84a7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:a92afbe76387219264fa7aec15f75d1d83e4928fa25bf75b0fe10c008b11a793
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:971b2f252bb27d9d1b43fa629736d6ae6483e13d01b473e75678913cb4d852bf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:c94e68edadbabc00b03757ed206211ccc50340e32da96491614b399429e5a320
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:4156a55d74aa53da702a4670581ccab72294e3687932beeb46719d9690db4e11
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:6290841938ec9680d63dd00c7dc01e5003eb889547d9902400416f284593d1d4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:3426aef7eca91a99b8d399f9384747ee350df9b2f744c6dbd9129a7c895cd614
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:1df315b75184ec5f4f00ab42e1df3031b58bbf8e1efdc6cf7ecaca4d8a3586d6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:00b9beff79b4403b130604b3e6a0e6ead3f6726f6fa48bc9daddf9c9cedb27c6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:301c1c8bbf11a192a573e9a7523ebe9566b8227d060eefe1a3fbbeda86062b89
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:b8ea0a4d959ef152ee595a52f8b0a5184ed195fc5791da55be928262c0d19314
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:07e27d0cf5cba876cb5643871bc7ed5561018877448076900c3c8efb15e8cbe1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:ee848f9a465c69f6f6d3e918e63f93eaf0ea57e61d0c92480086d36bff890c83
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:407abc3e5029d2590d9c7088b117b44857302a32e835a2875772c973d6b2adc2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:a47e8eb69f002d8000fabe2f6a4864e0b7ebc540184cf628e15fcba816f879d1