Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 25.x JDK (dev)

CIS
linux/amd64
debian 13
Tags:

25-jdk-debian-dev, 25-jdk-debian13-dev, 25-jdk-dev, 25.0-jdk-debian-dev, 25.0-jdk-debian13-dev, 25.0-jdk-dev, 25.0.4-jdk-debian-dev, 25.0.4-jdk-debian13-dev, 25.0.4-jdk-dev

Index digest:

sha256:3a3b5e809c60375850d6dc66df15ac13af570d81b6c7eed26570e02c3a52931f

Manifest digest:

sha256:5add3e2a77f5b8fd41710edc89fe4709cff76bd340aa62a5b09e5dd63f90fb28

Size

166.43 MB

Last pushed

2 days ago

Vulnerabilities

0
1
0
13
1

Support

Active until Sep 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:25-jdk-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:25-jdk-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:ffeb8f6e97b6d6eda4e606258a3ce837c22f8a1238388ab7c74a3a99c69d0009
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:94e1ef259d5d2739156f981ed14f186dff84df2945fbc634783f2257d915aad4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:623c2bfe1efa27cf4a6e5190902a91228d43a2e2ab306f3c1ea9089f4130671e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:b6be2c126d86074f228380c6a93bf85ca8e2cc63d56b7a2031aefff7e5c010a3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:42b6e7a575df58cc852df94efb78ffdf515476507611b66148aa78d69d60affd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:df3361df7d4dca0e1698bf0167b784b1700251bca34bd1d2bd85d99be9c5f50a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:b50a534d7931eef7932305f1efad7a0b0f5efe74d22a162618c1da821d15775e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:d166fe3a18fbeecf84b7e1f946f7bd5d7e7e6f011ab0c53e0670f66bfd5edd6e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:2ec759a8f32bbf15030a7153dd12cc3b667142efe9d3b354945a1ff05b726243
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:f8430d348d02ddea9b8650d455775e14d0cb9aad7a0b43630469118c0c01beca
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:1254b2d9102ab2f68d5c0e5a25406eb7d46af771dc790fec775a184cfda53a59
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:97294d526e89e18c0689dbd66ad1315e780a32ed7d4211a794f677f2515c15e9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:d4f132a2b08cefc3c20c95ba3cd403a49e997d374fcffbda8127fc52a6f8bb6d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:4668f766d0719748052c64a5c4abeef0515cb19aa8197cf30f8f8354661f9780
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:1ff4b4a7b98be783d47ffdd0c28134c50d8d4ffae701066dc9bb4540e19b9cfa