dhi.io/sapmachine
17-debian-fips, 17-debian13-fips, 17-fips, 17.0-debian-fips, 17.0-debian13-fips, 17.0-fips, 17.0.20-debian-fips, 17.0.20-debian13-fips, 17.0.20-fips
sha256:77cda864557a7012adbcda2f92587423a435addd760b8a9ae283b93f4b1ea523
Manifest digest:sha256:cbbd3c22f518634e4fc14630ffcd570f6906969a5e12925ffeaef1c6e3ab7224
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/sapmachine:17-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/sapmachine:17-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/sapmachine@sha256:c6473a02847d52e35dc8132ff2995ba9b51981530208e29d4b4c1da6ec23bb01 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/sapmachine@sha256:e9039159c50775933df40ee03e017f63147155d98770db906e649c3275fdffef |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/sapmachine@sha256:0cbbd0cb613736150bde3a45e1aa64304e591d1e66d0fa75d5437ec56cf6f9df |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/sapmachine@sha256:0e317e4d4e58edb7035baa63a86fc3f8ef75e03a44e4924b6a350ec529eaa3af |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/sapmachine@sha256:5ccce4e5c52299ffda569df3a96113259624e8daad0bcfde5d3afa5d20f6c980 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/sapmachine@sha256:2e3f56be44d0d2c017a32e234d4c28f26931e14149a26c26a044a7d7fce1079b |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/sapmachine@sha256:b32c94ac8f46092469c5c7aba9c70566ec81f48eab962a368586b09f23b640e9 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/sapmachine@sha256:d36fa1dbfe00a690bd62b5a78fc7836f5c7a586daeae206c5cdc50d93a4bb117 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/sapmachine@sha256:3a507041cfa533b8a05c6fa7e0e33ce8e762dd872755a49d764fbaadd96b3f8d |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/sapmachine@sha256:0dd9d3edc5ce01309b9a33488ccb835b4deb751b88d1a80c4cadd46c41fbfa1c |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/sapmachine@sha256:bee615bfd58611b74fbdcf560dc4bbc385fed9b1cc302f3390b8441f196f3622 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/sapmachine@sha256:1ed5c41e3d502f68e3cc0e5ac1e00da2e0b18985017c80cecf68ce45dd13c1a9 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/sapmachine@sha256:d8f0b3ba0fb03210559398ba882271e72257a6f12c2c8da78670fe5944bc881f |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/sapmachine@sha256:43b06918b6f9bba30cf2a3a5c81512436e4991b31f0b99fab94e002b09448129 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/sapmachine@sha256:c276c4c9be3f2330814d144811653552b4e01e593af961d44e107a8915ac9f98 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/sapmachine@sha256:cb3dc456c72ddb5059f476b6bb5664056f7f036a8c77119b885bd8d1a1af4bfe |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/sapmachine@sha256:ca5a6440d9a675f9fef34ebe0d9d0b0876b58b4dd6019b8bdfcf4d3945ff3f75 |