Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 25.x JDK (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

25-jdk-debian-fips-dev, 25-jdk-debian13-fips-dev, 25-jdk-fips-dev, 25.0-jdk-debian-fips-dev, 25.0-jdk-debian13-fips-dev, 25.0-jdk-fips-dev, 25.0.4-jdk-debian-fips-dev, 25.0.4-jdk-debian13-fips-dev, 25.0.4-jdk-fips-dev

Index digest:

sha256:ebdf1a31242b33e641fddbd74b6bdc7ec4019c3310d8d1829397deef17e39bc3

Manifest digest:

sha256:c1258e62902b3fc1a47154f1ede11bdb126d3e46d9c2d01a0a188d325082506b

Size

182.98 MB

Last pushed

2 days ago

Vulnerabilities

1
2
0
14
1

Support

Active until Sep 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:25-jdk-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:25-jdk-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:4f2606c4337338a83acb98cb5cbe9f3b57f02bedabf27b7d9192b9f292bf79ca
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:79eafb72301fad24a1503c1f6fabd850561c14130e1c3123ef73731beb3e0f73
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:bac96e984ca3bbeb8391069674bd41c68e9fa46dfb08c7e8be71434f785ae154
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:8f83e7c94e180d9b778baa15ee88ffa648e8fe54841774c18360b92c570ddf79
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:73ea5787d69149d71cc062c25d06c72241ab576ce15fce8e806ea000b8245636
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:47a9c59ff9d052a8ca0190163b5607b3a11a3da93a9efe8906acd29f7cc22380
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:805f81fc143b72908134bb33f84efc660d1011aa995ebb42b0fdeeb15feabb6d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:45c050e41621ce86d2fb3651ded3ee9a8415f327df77f185ee52cdd0aa5bfeb1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:7f15b37579843511a84326cb788c996dcad9e6e26272f236559abbf791e6f6d4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:71a3348796a09abf3e24b9fdf0334f3857337eab24d438e54cf9c91f61a0bbf9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:2a1c2d0567ce6d80fb06430d7abd569935eb6b00a191d182144442c5cf9c74b5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:3f98ee621bfb34f6ab95eed9db665f9cb02aa0d3e9d19933b8b957636a5404c8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:f0cb85e38869896b31f7af2d6580c0404c0d100e82a6f35817f67f9a490d04c6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:86d0ee41698c75766b8966eb1a0a61af17de020b09aeb156fb56e1a1ad8f96a4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:4219eb6dbff49613a4cb91f98bfaea8fca1f149628395dc65b9f55146ca97206
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:e0a7c90c51e8630b703b40528375002ca67985ca8ae9d5c872c723338831b316
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:78ce769a029ae1e4f92468e1d54540f8b7297730c185e07693b92a2b27ef14cb