Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 21.x JDK (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

21-jdk-debian-fips-dev, 21-jdk-debian13-fips-dev, 21-jdk-fips-dev, 21.0-jdk-debian-fips-dev, 21.0-jdk-debian13-fips-dev, 21.0-jdk-fips-dev, 21.0.12-jdk-debian-fips-dev, 21.0.12-jdk-debian13-fips-dev, 21.0.12-jdk-fips-dev

Index digest:

sha256:e7c068d2e9c91fe053f134f11f6591d3d68e92d52de43fc304a3f5b8fa203d81

Manifest digest:

sha256:8cf8e78a5f1465f89b68a765eb0322b430c81b7ccb838f555f5d3bbbb72999b7

Size

176.23 MB

Last pushed

5 hours ago

Vulnerabilities

1
2
0
14
0

Support

Active until Sep 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:21-jdk-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:21-jdk-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:d5a5e6c863a4215d91a539fb174ad8e9c8a04d9206c3cacb078ce78b2d410a2c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:bffdcb4779525fdc27b31da6e0d9be231108a3559eb880d998e68b7ada477600
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:0fd59c4900559059147add3ff56c2fb0cfd9940d37a5184b3487d4abde03570e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:390d5d3acabf3a79dad934e319d1fdc60e98eae132829ed4685b24120a03e7fe
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:c394318230252b461bdeba0f7dbadc9f21f1878268e166db7ce57f03b7f02319
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:5cd1e910dfee449f6b06efbbacab5840b14d6186a8cdcedc21679bf21d736cc6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:ce9dda214c409cd2bcc47fe39cc43d7ba8df70c40e68e7ce846523bd79823d11
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:0053b2a4f782565b8a2e92f641696eefdb1c5ba7d50c593d7a8b38fa4f7f51f5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:d137f268d17a1a432d176d52f7acc68f5657d92b51c5a01dc4681775947bedaf
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:820e638c77c0051c36637dfd5aee86ef6ea4828ad7ae2768ceb74a1e645f9b2b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:d9622a509f43fc2fbf5c02b3f5bba1438b80a99293b0b5524775c9906dbb5d75
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:953e8765966a1fdf472f30c58581ec4f447a7b233b3248734c51584a711079e0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:44a52cee0ce98215ab274eb127a86330c9fae190c575c39006613ed0a323db55
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:46ce0cd5c116651dff815a532b128191df6ec3d32c53e1079cbaa7345c049f2c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:a52b6fd8e8dfafd1bd942879f662972215fa930bb7bdbcc201d06d6d13fba9c5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:56fba3339d33937a990418424ec3d0d93773abdbe25f3a43bb48fd03600e750c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:89b0b8197c518198bc3580fab9deb87a29e11b63e70ab85b6bd79e16b59de7e6