Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 21.x JDK (dev)

CIS
linux/amd64
debian 13
Tags:

21-jdk-debian-dev, 21-jdk-debian13-dev, 21-jdk-dev, 21.0-jdk-debian-dev, 21.0-jdk-debian13-dev, 21.0-jdk-dev, 21.0.12-jdk-debian-dev, 21.0.12-jdk-debian13-dev, 21.0.12-jdk-dev

Index digest:

sha256:d554a6d98b4d8d3437e1e3509237acb5c71d71cad7af0dd18e02c8be86353dad

Manifest digest:

sha256:e28035c492f85a8a5b0412356c1e2fbe9fb1edd751ecdccbba0c9fd8cba9fb62

Size

159.73 MB

Last pushed

3 hours ago

Vulnerabilities

0
1
0
14
0

Support

Active until Sep 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:21-jdk-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:21-jdk-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:9c166252c98d51cbf2abcf2d6dcddfe43063fcef8336cf0ca457a8312a24a614
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:02f6916747bdaf7c8ce14520c6ed3cdbec81776da9af5e29b52ce9e7921e264a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:24aa5524c6ee34386a13ea4c5c9a89746e876b9a0e75ef9c69c0381b31953ae5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:a5b8d26a98e2dc5e632cc2c6c08f1c0bac5a10a4ea23da5cfdae2ca2b59440f6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:f2892215df45e4e65fbb2e68b745d07487e4500e932e16eabc77a032e56f13de
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:0e9b2d0202cf93e31905c4134fe2cf1776de595651982a916e58c41ca65d4be5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:3c81a00e4e255cb3258bcad5ba06efccfcfe7115055241d64cfaa4bf5a3c6bfd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:6992d69cf405c6b57f9a2eb093beb7a602dd332f64c24bcac301597098eb9146
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:ac639b8b0d2d2f616794a2d361daea719683bfde151687c7b18763dfae0822ec
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:e763062fee4120b9267138ce8bc5c7edc4c2ce1d1795eb8d3788594b876f28df
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:8ef0a395a5589a196214d9d4fac4367967a844c6ce812f650a895d7439db522a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:744f97c8346c2080a283e25523a1c94e2211ddd5fec8313281d88bfbe8db800a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:eb65d518dbfd4655ef0ef0cc7e39bc943c21a09f9f86ca9dd5eba0e38dc07e54
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:0d86092a7054edbd1d95bb9c3d800ed09e53284278ce81ac7b77f7403a14c93e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:6e9a184c00ee430d89c49b975ef66f5fa435c7b5d96ddeefb13da0a015bc2e51