Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 25.x JRE (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

25-debian-fips, 25-debian13-fips, 25-fips, 25.0-debian-fips, 25.0-debian13-fips, 25.0-fips, 25.0.4-debian-fips, 25.0.4-debian13-fips, 25.0.4-fips

Index digest:

sha256:f79f6346c53806717965c2e364f3cd38b40c9a5fd524f7c339bfcd4308679344

Manifest digest:

sha256:4a5b4d2843a57caace5980ea429a27994a0eca74395ea3d9cb394ef485cc8cbd

Size

75.93 MB

Last pushed

2 days ago

Vulnerabilities

1
2
0
12
1

Support

Active until Sep 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:25-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:25-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:83ef3e271eac3d07aceaf41981dfe9e7125d33d1700fca19ccd2163e3f81d123
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:c868368647c92f2d347e0e9a4ade16fb8ca73d2234c03938087e3221418fa697
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:cea7735b21cc781b1f794d5c0b57488b80b9f84d05ed194753ff4bc1baa0b2e7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:9e61fdad0061a2f411205908247647428fc4e1bcb97f26a3a1efb3f70def65e7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:2e4e1e8920128d42c3d564e070926d9d375ffa767b5d0869462368c9452ddb93
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:d206fba7da25e6d0fc490393dfa0ebd81bffafcc6d0d5e11d549f4e9222bf75e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:cb8d703b7df32a3bc6209aee38be62813658fc9ea97342645da16c8ec8d519f6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:44ec1605c5ccae28f21183843b57a536258299bd1a0ea565c70352f2eedfc083
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:f7b64c11bc714ae865b15041bdd8b5a0e4ffe3f56d2d7db803393b8f136d1cfe
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:e7ef4416614c40d3016919860ccf1a70cba911fcf06f2f9064bf49c29d651d35
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:931750fd5a65303b070cd566f1ecfb18c03a7aca51e06477d6759d4446a95491
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:0bcf7e7306cb03d0bfc5aaee5c36989845743d74aa35a09347853926afa66e68
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:70a94519cefbc9a11d2b29daf8fe11e006d9a0071699d0b900f061bf3d368b15
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:308ee7d62da3bc8f87cc90771b2dca1af7d51c961b4cfddf2ab3c006ffd9ce1c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:66e53d6da23244bca26c6e903dce31e593288315903883da537412994838d0cf
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:995a5128ba5093a9a0132ea7bc34a2f0d6332ae2660e661df883487516ef433f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:ae84f9e9df68478d69654bd468ecd6519416e1505ebe99495e45d10fb53b5775