Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 26.x JDK (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

26-jdk-debian-fips-dev, 26-jdk-debian13-fips-dev, 26-jdk-fips-dev, 26.0-jdk-debian-fips-dev, 26.0-jdk-debian13-fips-dev, 26.0-jdk-fips-dev, 26.0.2-jdk-debian-fips-dev, 26.0.2-jdk-debian13-fips-dev, 26.0.2-jdk-fips-dev

Index digest:

sha256:69e3beabb2d38e444d7b408a907b68910bb659da007afde7305d22bdd0843e07

Manifest digest:

sha256:f2d3949d4e2c3a67c33a1c08ca6747344bf0a5677f6949272f4654337d763d1c

Size

102.72 MB

Last pushed

2 hours ago

Vulnerabilities

1
2
0
14
0

Support

Ends Sep 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:26-jdk-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:26-jdk-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:fa7eef12ec507e3fc58f8c29a08e357519b398008a9afa870288111921e6176e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:9d3f6a3e360e92059710bc76abca5fca500b9a38ae0f8fa45279d91a05f48533
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:7f5efd7df511eef37b947e498e13b3a62b147a5e0c2204f45ac8fb27b0d70640
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:3fe7de61d3da70bf7fbd75db0b905861f787a775ae23bdaf1b659f45fb4e9601
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:19d3028598790da08b4a8216862cf685b6d0dd4360665dbe1df8d4c08d13e0ba
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:5da96abcd270987667301e3fc9f914434512df46d0d3b6c85e7afae6ebd4f931
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:46b214a7446dd90db0f3ce7cdf87769082eeee81bddd05db6db3506b6d40f4b4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:476cd83b30bad0b8e7d07bc7db81af8b43c1c4bbe533f90d0908dd7492327149
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:6c43394def85a23e29a640fb27bdd9f92731d6549f7db00384e8e78774121756
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:15b6fa12772f1c308691db770f1b16b8fdf957098e1a2d7dc2724c009803d5d7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:a167adeed50e061fa076d721c0f7af6ce43fe3b8b5fceed725e0259960a91863
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:cb63b46706398ad8e9bb2ee23d51328588e5af9bd9393bac987bacca39b98f76
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:d72fb33c3df574fd52dddd0c8d3c633c260af19f92f17eab174a1ba6e9f64772
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:52ab25f55c1083f39532ef9b7b0bf6c7c2c969ac25fb48d923b47dd807083f82
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:0b1c99d69aa5d80a5519ccdfe16e80b519de37385b722653d6a369168cf79970
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:12d2213570bee7c54f3abe3176b2e1155f95a3528ab8054d47f7f0bdf9345505
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:25123a5e6011035923362908bc6f8625574c41197cd5747fa156d324405c7401