Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 21.x JDK (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

21-jdk-debian-fips-dev, 21-jdk-debian13-fips-dev, 21-jdk-fips-dev, 21.0-jdk-debian-fips-dev, 21.0-jdk-debian13-fips-dev, 21.0-jdk-fips-dev, 21.0.12-jdk-debian-fips-dev, 21.0.12-jdk-debian13-fips-dev, 21.0.12-jdk-fips-dev

Index digest:

sha256:6e940a8be0f313cc67d3c677cb1955aa5471ab6dfe381d01fe98e6768e061400

Manifest digest:

sha256:525711bd191c613a454eea2c035a0568171f17e83626ca4b1fca2da9789f85ec

Size

169.43 MB

Last pushed

1 day ago

Vulnerabilities

0
3
0
13
0

Support

Active until Sep 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:21-jdk-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:21-jdk-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:c423b739e41a98ab4af6acbed58a60137a03c21e947a1f5b774f906bbd7fb952
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:e681f175e9e6af0ce32b2c2104282b7ff71b7e3c818a002e382c75f76d6e35d2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:7a1983f64f9405dd635a294caad0cbdd97025e38d74bc1b1a109bd4434a2a4f6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:8fc2f6815531934e9e0bdccd169ce8d454ecd928ad1f62c65ec67d87d466696d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:60d8c1f82b3eae5ca4c15896c6f358c67a898d80aa640efcbf65b455e1874cd7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:22ffdd868e27fab6033ca47f01fe9e56164c605f4de43698107dc37477eeda35
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:6e948b6ead3d96aec6db3cdeea269461917975404fe566b591bad30d5ab2e341
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:d587d3b487aae25d0a485e14114ee9547d4591c74ad2fbaacba2a28c8603018e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:2586c39032b0977f1a4d683edf96d7cf351363b415cc9dbc1f879a68951b8982
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:ac63d57b05db377597b8f0a2b30160693265d18a660fd870deac133fd02ec4d7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:80a54506a556fc4bb5217120c891cd86fd901bdc2478595487f8802fe448b590
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:5bea02bce96780484a8e0bf2cea929c3bd6c3053d33102eb441051395f0b04d8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:cdfdb30eedd630b010c5bb693ded78fd050252574ac922783e917063eb40a194
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:5d08e61071e78e51dadeb1643786768330ee2325329a05547ac3e523a127bd40
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:4489d1d675e240c4d0fda77f9f83e951c163be2f03f05d647cab03ca9c69c2b7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:599be67cdb0e35fa0e04b0c14c6f7b62a8e08979d11a06825c206b2a03a263ab
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:d5a59f0d7360f8f7027a012a047e32368c0d35e93e7a9fd4b51df5bc0ee1b20c