Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 21.x JDK (dev)

CIS
linux/amd64
debian 13
Tags:

21-jdk-debian-dev, 21-jdk-debian13-dev, 21-jdk-dev, 21.0-jdk-debian-dev, 21.0-jdk-debian13-dev, 21.0-jdk-dev, 21.0.12-jdk-debian-dev, 21.0.12-jdk-debian13-dev, 21.0.12-jdk-dev

Index digest:

sha256:31f4c34e83f2743f0536d44b517cea6b7d1a8a244c1d04a7547080999a0d84a9

Manifest digest:

sha256:6af276a5b98cdf680b8aab414dc06995045b09c5e82c42e490465f4c3acd27df

Size

159.72 MB

Last pushed

10 days ago

Vulnerabilities

0
2
0
13
0

Support

Active until Sep 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:21-jdk-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:21-jdk-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:fd7de969b56fea4bf2a202b7d7f4292c0d04e556230fec56a0a4116b1b5b1cdb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:01b5a7d373e14e6b77f545eedcf598415eaacfb740eda96b37e4b5b1c53fe182
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:70c7e071724fde6745e689453c9234321a43bc34225f4c5662dfaea65c2c4740
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:ac8e3e6406922098b75656f9ba01a0259dc37e627d35d9a2a39e50486717500b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:eb8467d7cd27fb57809ad3cbc8aa74e173be88d0bbc38b9af052255ad6a3b404
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:7d1b3b03db9c25378410093d266122c2a02294f328b5d944fb7b478f869297ab
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:c46f205a84e885424636e68fef7781d3034f406351e597dfb898879e65c1d5f9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:ab03533da20c4e51972c87f14ba996c4ce897dd8f3882a95a45a349a85262f89
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:233580d01e07ef0e7f37aadab7d4c83235e6dcbfe2fb2bb60228f92b003b2b1c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:888b0c2aacf65731e8d2f7b5dee1c0093e6cc33fd050bab9213a1489a1172cad
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:d826ab15e8d6acc3b5af1afd93abadd3c65a99e34501a997af5c4d8dcadf64e1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:26a05820881ed203ba11e9b16476bf2029719e1af3450d690f9ea2ca1f50d747
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:052bef17a8fdc02e77bbafa3995e2bd803bed96e0ff435d61843784d94a1384d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:956807a431c0dcfd922c0b3fdd4945b9f028d2b357fe2c009dd515b35987dcf3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:531ae1c1771a81e1554b9924879c250a4406b6eae3bce69c2eb691f6fc715c99