Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 25.x JRE (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

25-debian-fips, 25-debian13-fips, 25-fips, 25.0-debian-fips, 25.0-debian13-fips, 25.0-fips, 25.0.4-debian-fips, 25.0.4-debian13-fips, 25.0.4-fips

Index digest:

sha256:71c12d96e9d36df645f22850bc2fa58b4c40a8207b2ffceb46dd77e94212906d

Manifest digest:

sha256:51f45f2333c74b6619d01710360b67e05a375c9ae717cf4f8f97c2a396ec345d

Size

75.93 MB

Last pushed

11 hours ago

Vulnerabilities

1
3
0
11
0

Support

Active until Sep 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:25-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:25-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:ca7d337d22d3bd01f9b1e0ac15e544888763d04ce41e0721e9b619cc93291058
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:1fe6f60fb40c45aded3593475432b8726fde15ce740f56df600b4e459ecfdc01
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:88fa2c8cd9b9bb5864fb4c1e2255b85b3776fa6fd3ae0c64538156700cf3e298
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:a6f4277a4a548ef0e0d888899fdc39f8dae5c670f53b5d1260d5bd918b7fb0e7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:079c9636dae50db829408cb559642e756352b66115f542302fdc0edd08dd5584
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:131ff4bd3f00613fdba297dc1257cb90d03095db96c1b95b36d898388f4ffe48
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:4349cf9856aae6889d96866bc6f9a54ea0042d5b48e8693b39000a053969e1f7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:ad662fdc599a39e8cb0a34d22c263e0e6329694f61a59fe09d8966669b8a587b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:484a23795ddf1e81f9db40b2d199c1938c4988e815ea14f9b9a2f39e94913dd2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:698d7b3e0e51ca4a9aae4e1244161639c13a6c5224a23fd025e7061b3219d24f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:6c80dc1aeaaa0f1d89fb715e32bd7f3188300360735ffb559a28bf5cebe611f3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:26c04d1e751d59983af8635c8bb731f89035954a99b3792071bdd6e3440ee024
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:ceac65f675a9c347348bd1943e653653dbf15719a2bcde7221fa4d7a17249376
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:1da8a77646965d6953e3e74aad50789f3754d77516ba5ee33a1c71a36722f4d8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:0157f39f515eeb5f0777840f88945e4bdca771e7b77af82a2b2eb3b15fcf5ba2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:fccc330a47588e0c0b0ec0079b6811f6bbab46fc13122ec31261c8d7f6fa941c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:303eee0995ef3a306d109cadbc824cd0125cd17628ab929468fa39c9a240ee58