Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 17.x JRE (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

17-debian-fips, 17-debian13-fips, 17-fips, 17.0-debian-fips, 17.0-debian13-fips, 17.0-fips, 17.0.20-debian-fips, 17.0.20-debian13-fips, 17.0.20-fips

Index digest:

sha256:84733aac7cf06300a1a6d43943b129ce5ff1518abf299caaea4ddd84ddb25f07

Manifest digest:

sha256:de1319e9fc39b48b2c68e82b68cd35c8d67c67639565175eff6e3ddac2fa2bbf

Size

74.40 MB

Last pushed

6 hours ago

Vulnerabilities

1
3
0
12
0

Support

Ends Sep 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:17-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:17-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:1c3e93a195bed6341333ee8ee91c10492c78864913c9566c65a4375c9cac3d3c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:6a2411f6ae7e33bfbc5a548915756651ec59bb8095db7d777ed883a7f867bb44
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:b7ad241ef84a4234d2b1144d165d749e7cea25ee3a9170fa9bd7a2c827e70512
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:14a8eb684ab9be7c0d472d72f2ddc2e2de6225966eee6611422349a83d2225ce
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:a50ee823af3013fa8e7ca20e447fec30973d0b920a5eb7f467ec81091d106a11
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:dd96b83dd172cd6040104347f12052c3feb0abd46a1da8a4637e4e04a4c4bcb6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:ca45b41c844bdf176ae12c372c98537e445473ca12f6fe70794208b096208299
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:e32b31612cae232a003668114b5e0c6b18cf7153ea6420b36a92e8f81e87061d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:f50c61f3ca3915d2f77f99d0da6368f4c1bfc999daec535a8dcac43083415df6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:27a95175317310c10c2ab765f860b8bfaba8e64f59358b0ce42263947360485d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:eba201dccdf407eeb1ca2819657d014694fe2ae2664239c90b94f9ca5d472737
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:c3a447f791e0d4b4621cb6b2ddf3bc2a24f779a28386ce39d5872b3b60cfe79d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:a1d9bfaaf8d948b90ec037d5889ee359b170493b61ae41f5f76bc6ccf72161ca
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:29cb1e6e94c21b82262697d8ee26b44ef366652fbb930628201eda69dd7c086d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:9e89a4d34e93fb27517a6c55e80c22a16e1f7744df47c4e1b681fe865d352b04
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:6aa97d6073afa1dfa7273a6a302d1d544a533a40aae699cbb12b88124b849c56
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:f4d4b2d64cf75b34c20813fc7de985fc524931793493abea8c2b67205ca9e824