Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 26.x JRE

CIS
linux/amd64
debian 13
Tags:

26, 26-debian, 26-debian13, 26.0, 26.0-debian, 26.0-debian13, 26.0.2, 26.0.2-debian, 26.0.2-debian13

Index digest:

sha256:270572bbb5abe4b7e1204704be738d04694fd7f58b4ae8a7459e7d2b7e69b678

Manifest digest:

sha256:24641dab3c5e193f46f174eefcbc9aa8221a6f4c6e9d7ca66c9ced302def6f67

Size

56.12 MB

Last pushed

2 days ago

Vulnerabilities

0
1
0
11
1

Support

Ends Sep 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:26

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:26 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:f8204f85332b070822a1fefff83a7fa350276229a28dedf519e37528fa91585f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:600c85afe0be5510e871b1aa61cb7014de8873121f8fd81bc5071893c750d526
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:529c72a9e4581bb0c9b5eb5c23de4b5712cef1593eb475e0a2c352df78aa426c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:fa078c8b58f26b6b61c29aaa2ae3513d53be46491a4231e7785da066266823a1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:f12396d7f9990cd700c93ad35c86777c1d8db396a823dc3259cf2489eede7974
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:386fdd494970f819bebe4739c1d4d15eecff787eab28245199ddae320a42b08f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:177f1c30ef7d996f2a63c7cad6e56ff9c6f97f4ffd7cf8fc7cf32638c8f065e5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:1bd1bc82443cb25026fd152b49cb19e994362e3798af9cb8e63e36103b951f98
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:cb9f828fa46575cdaf0a0052fd75708c2fe10398f22e677b42bf2140353bb796
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:aebdcaa6ecf2948487d4dfe97c31811e6b1e75a8fed507564f81433c16144c43
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:f628c027494dc256b9de91f4970b1145d66b6bf75da26c335f914b144c54d4a8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:4ad9fb6e94daa3906506ee7c00d0fe9464e411eb6c2401b00984e6b580a98dde
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:5b7a2c8a3a827bac28a35515e0525f3d0dcf217605921cbe1f5929d03726b949
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:ed27676e7b0a60ef1b4c424e0080739a6a8e6919eb9ba9293963e6b69db8515a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:8a6f8484f047287d06e8682f67ce9ad59121059c9a3a4d837688cab34d213641