dhi.io/sapmachine
17-debian-fips, 17-debian13-fips, 17-fips, 17.0-debian-fips, 17.0-debian13-fips, 17.0-fips, 17.0.20-debian-fips, 17.0.20-debian13-fips, 17.0.20-fips
sha256:b2798c5dc84889283ab85e64917bd97818bb615041c0b499d36bdc528067b938
Manifest digest:sha256:377412d3d4206b941132235cdb32ae43e9dd1712d1986b12276ce1618e22d736
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/sapmachine:17-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/sapmachine:17-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/sapmachine@sha256:424a904df742bdea4c54be53d60b23ebaf6dc9e5ddf7463841ceb1278a7d7e1c |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/sapmachine@sha256:341ad80f2d4d1e1a5b34ecdd4c5b507c17be950112ace6cb7044e1d877e679ea |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/sapmachine@sha256:9071672c58aa7e0c7ff1d88b9426829fb23f7e32220f718b40d7242223f6287f |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/sapmachine@sha256:9d7bd9012a52db8ccd1676f1382b86c6bbbb231f6d72de43c8b7a4344d7a9bd3 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/sapmachine@sha256:c2c15d2a87e38a8ff66804fcb0830c8fa67dd719a2172ba96390902012d78fb3 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/sapmachine@sha256:5e9a0c95696d18356c3cc7effb9ee1538f186553963c48515281f7120364364c |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/sapmachine@sha256:5cc6ba15674ed38972bbc04ff815decc48e617ceaee7e3b7c5d410c0ecb979b0 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/sapmachine@sha256:b580a3b1b0a7cbe43f45812f2250b9171af5ff1a70f1b75de504d1baa981a813 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/sapmachine@sha256:1ecaf2b176fa18e52f6d89af3ae1a8440022b2360325b907268b378ce011defe |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/sapmachine@sha256:f703cfb14f50b7e19f55e47ec970b8afbf319efeccbfbbcd5f804a8e64072f18 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/sapmachine@sha256:0c9ce73fb9bc72959602afedb6e1218e31483ee8b87e28d6503836d54f40e76d |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/sapmachine@sha256:9e1e149fc53ce802c3af782d11055e44d30c9c2249a4decade4407025853dc68 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/sapmachine@sha256:ac08005b51f71ed10aa3e99fda38737857e762bfc8f2ff53851f408009a2cf35 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/sapmachine@sha256:24b165051463035d7374c7a040aabab741bdca6c2830e1075e2c8bca8c74970a |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/sapmachine@sha256:4819dc0168280cc7d33b0e24a7abc6c6270986fc3db7002ac255560b3c3dfb14 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/sapmachine@sha256:01e694845436cfb4a0ce47d4d4ebf2a3d24a91fa5ad5dd6a27121aba198eede8 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/sapmachine@sha256:5846181e8ed7e1de6cee0e9038526e4859f616c1aaa846870171de6b7661cbfd |