Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 17.x JRE

CIS
linux/amd64
debian 13
Tags:

17, 17-debian, 17-debian13, 17.0, 17.0-debian, 17.0-debian13, 17.0.20, 17.0.20-debian, 17.0.20-debian13

Index digest:

sha256:36e753a16fe1fbef660cebf792a66fe2256c8d265eaa805b6c316b94971720ac

Manifest digest:

sha256:86e03158a0880bbd347f3516dc444d54c3c7801bf7f44542b4956bed22867586

Size

53.90 MB

Last pushed

7 hours ago

Vulnerabilities

0
1
0
11
0

Support

Ends Sep 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:17

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:17 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:2ac54bb59eee39aa7561f527e4ee88075c5fe84b416b79a89650595789d3a57c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:ca0bf7a15930faeb7543ea320f3dcbc750e312f2e21acb242f746fd7cef7ce1e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:96a82172cf342a1632e35c2003bb3bb25e24eafb74412348ac9cb5823b0ccc72
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:a415109084f2919fd7fad30972057b976fd01dda65782fa38cbd58495162c2d5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:f627ddfc3cf3aed9e892354ce48df0a31dcb34f2315dee721dcb1bedd607573a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:e28ea14faca8c8659c6c57b0c94f9a6bf9fd9469d04fbdb796bf026b8028baec
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:1e1aa50e79391bb8700655658fdaeda4575810952faf6431d19b5e6efd9fe0a8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:68a53e569411122fd7d9dbdf1c88cff7358b8de1bca465ae1f56e3ec5c62cfd8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:e68a70e35c4bcf91de8e5761b1cfea956e52b2d9e745b05bff79ca24f2a7c875
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:c1c3f890d455e98be8cebebaf406495464967b620716ac32d6ec28a494e4ef4c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:c8586d77668cacd291a9ce7f0ff80a16af701b177658bc9d595a1c8657d72145
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:3ed17d92b1b34caf4d37b5736ce690a716236a10cc5d3022856257fdb4b0a13b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:a1ae3d66c6359ee18a7caadf5b10c81b7b470213763a576a9962c4188d49f059
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:759e8f3d3b9c43bf3a25ad1587a7003d68cfce339383fac18309f6fdc4e468b3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:7bb005a69008c6c47e8cb77cfd58e83d8c363066a2cecffacfdfc9b0bdeb4024