Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 26.x JDK (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

26-jdk-debian-fips-dev, 26-jdk-debian13-fips-dev, 26-jdk-fips-dev, 26.0-jdk-debian-fips-dev, 26.0-jdk-debian13-fips-dev, 26.0-jdk-fips-dev, 26.0.2-jdk-debian-fips-dev, 26.0.2-jdk-debian13-fips-dev, 26.0.2-jdk-fips-dev

Index digest:

sha256:60ffd73433c1cb5b74fed81be7e98f74704280da58e7772879a8142f1a974bac

Manifest digest:

sha256:1c1b2c40ba1e7e49f5320f355549dd37a3677d0db9e2f75b0c5a2b4ae62371e7

Size

102.72 MB

Last pushed

2 hours ago

Vulnerabilities

1
2
0
14
0

Support

Ends Sep 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:26-jdk-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:26-jdk-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:ca95a671fff79d9bab4b0f5a3a8463ca265d2c9e31475f7a4f0be2d150b0da3f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:5dfa6f011d2f00b742d13c0d501c6df62c771904956e6efae09f596daff604f9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:5dedc1bbce869b308f158df7dcbbde7c5de3ae69ed27758c15015fa70aae5803
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:9b34b00c12dce4c7ab508b10c8730b85fe8fed8349774e56d0c3d8ec7daad149
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:51620fc4870bcb7ec4ea399d34fa74de89f39617a816b178abce2b9f8a5ef287
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:9d9d671236b331fd74c4b33e3cc585f7e76f0df5695f9aad3b852b2049740ed9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:c3cb800f683d7a65f7527ad0c3dc5fea40834b864463f016a87f59344d4c1284
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:3b1b3664ffdca5c53f731190f7d4497f19afa0dd2aac71ac6bc246ac766f5c03
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:795c3a853db60c980bc33a56e7b24f4c2821aabc2dc50bc9d1c10853beffd8f7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:d923f0ba4eed463066faff418f4e3c92cb46019bd3ea69d1f0c0340c91a2da86
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:904c98a33df3dafb2a9aed4335c1ba077284e0d014e7a5659622aefcc5f781cc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:79861eb0eed7a18c6377e525f96a176cbae4f109329a7f0e902f59bf2b173277
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:fb0200f5f6c32897a5556919741f816b7685f3ac6f5e8cc40598f8990a3f11a3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:e69a8a2b839e79e49e1587555c9d89bcfcf3ab147227a6359f89688495014ac1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:d5a99c3d8b20bd75de7d0114f2cd66cca3d0415b095581a724452ce5111821ff
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:c1438205f04dfc2e46817d4ca4e6e7c55bac28a94f2de3b516ce23d5cc500a1a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:60c8e086a087174e853b98d6bffa93994c30f502b8f56426db44332955da3ec9