dhi.io/sapmachine
26-jdk-debian-fips-dev, 26-jdk-debian13-fips-dev, 26-jdk-fips-dev, 26.0-jdk-debian-fips-dev, 26.0-jdk-debian13-fips-dev, 26.0-jdk-fips-dev, 26.0.2-jdk-debian-fips-dev, 26.0.2-jdk-debian13-fips-dev, 26.0.2-jdk-fips-dev
sha256:49730335ff67d766f5af8998f2249a06e93c6d16ecdc64857903ba3b8f19217d
Manifest digest:sha256:ce72855e228c68fc1eae000a64ab79450007e08860cd3278f31a1f58aa4edf58
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/sapmachine:26-jdk-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/sapmachine:26-jdk-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/sapmachine@sha256:6af17a453431390e51838b95ded675d7cb570019c66b22663c9b42bee4d488b7 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/sapmachine@sha256:f5cf30f04593c9968229bd0040854e9c79199081c5ce5682c5b02d204142a668 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/sapmachine@sha256:1e183f19c95926ee6daee072a3078a19f84d91f36b490026e4658fecd3a8dff3 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/sapmachine@sha256:d7c1cc118d9baafe674b52adfa5954dc1b1a27f73377c52f959c1e37113f8a3a |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/sapmachine@sha256:e71c75413284e70a9722c242b0d5f715e5b0cbb81e15793dd6084d7c2d59b710 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/sapmachine@sha256:d48f5e215e1992c894897f7cc535cc866306d4e3cdf89075592a1212406c2a18 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/sapmachine@sha256:39cec7f2f1804b548ebc8c031413efbe6f5e241805d78c0cd99e33173510cd29 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/sapmachine@sha256:085bb39d52b8f42aae771b68823438396233ab526e048a9f19e06ef99c858387 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/sapmachine@sha256:ee84549277ef7790902c29e6df86cfa11832daba54ba97a4218a54cdc7b70526 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/sapmachine@sha256:1f3a9bc5f19c47b2550fae4dc825410977e7674fdc5f480ace7614ba323780cc |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/sapmachine@sha256:b13a99ea1fb9c0a667fad10803d0e56ea16954397a2c8fdb9a349bc746486c53 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/sapmachine@sha256:e7f819f2c230384ddb678d9bbeb269256a875ea80e0c5b9ea3c75a14157e3543 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/sapmachine@sha256:9311f8ef858ed0a15ed35f621087cf302559c11e1f5e4c70e4b2f9106890a440 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/sapmachine@sha256:0195ce8eded48433b6e1ea35413cafd6668c87ecc7740d22b0cd41e7e03b52ac |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/sapmachine@sha256:8da20ff9b792654e942791daef5cbd090933ade70f60e148f97a8c936e9d006b |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/sapmachine@sha256:2d57623e2e97168e05a1be0e6d5796715500601c40720d6aea1a6fd2f84342c2 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/sapmachine@sha256:b0380e48cd7458ac64e23d5b04c080604e28d3919da01f189768560460b9b97a |