Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 25.x JRE (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

25-debian-fips, 25-debian13-fips, 25-fips, 25.0-debian-fips, 25.0-debian13-fips, 25.0-fips, 25.0.4-debian-fips, 25.0.4-debian13-fips, 25.0.4-fips

Index digest:

sha256:332248c3c6cf8bcce777f0c06499b1e76e9b8fe52b6c90102a5aff778d05f177

Manifest digest:

sha256:c42cc46aedc1450f4a7e6a6d1a107efb929f23d27de64e0b6dc16022265820dd

Size

69.75 MB

Last pushed

3 hours ago

Vulnerabilities

0
2
0
11
0

Support

Active until Sep 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:25-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:25-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:209c544b81fac0fb47979cc39078218c2c81b41e1fc76a26a0889fe46ff15c98
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:ba705b4a5cc40617b29c381812a69a102ca2c7602620d4ca11e35f9777c0ec08
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:d030319ef7e6ee37e9382416078d8b323e149d2198635abe1d1fda29ede5e808
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:634ed7a52ef5d41cc89a3f82113eced702fb28bc1234729ac7cf46db56d1ea90
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:1f0722614b16dc7d6b3475243b8d44ecb5202874608919e73c5502334ba7c6cd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:9b8b77b27984b4762a82278057db19565fd17a250989bdb01323bbafb100c7b8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:3c034b03f4ad2bd2cc9e18edfba4796d001e8eae460f2fbf82729c0cc8ded239
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:a02d8f2bd196d675f4be426804e67995dcf29c5e5932df2f6b8fc57063df8304
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:554a8d8d74aef06a055e2d07f8c7d7d985cd5c973f501c16eafeeb72ff27b9c4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:422ff8f450fb8ef635dde172b62b6be68956f002b5cc1585c8362be6c23be3d8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:f17a955a081e7cc719c10cc81870a6a998d5fb18100c65ab6a3bb45dd41092c6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:47d1a23e4fe67319587085137c23f86d60180821390abfe1605580d1dcb14eb4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:6c809f1360cb1f89b10ed4da643d333fba82117d30b3b8a84adc174609370ea4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:05f45e47e9004f7bd632a7880735ae150ae149701d1eb9316d82a4a34a307fb8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:05cdc890acdc254e4018e0d2800488ffaee19d58ebaecb295a9ecfb4217f79e8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:8d9babfe241d6ebdf9b36c3d9aa98bc5faf17a195d03afd6f9364cd5c4de3fc7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:d41aa53a996a767f67cea9449c0e9942590f03282ebad7511a47f05a04b193cf