Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 21.x JDK (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

21-jdk-debian-fips-dev, 21-jdk-debian13-fips-dev, 21-jdk-fips-dev, 21.0-jdk-debian-fips-dev, 21.0-jdk-debian13-fips-dev, 21.0-jdk-fips-dev, 21.0.12-jdk-debian-fips-dev, 21.0.12-jdk-debian13-fips-dev, 21.0.12-jdk-fips-dev

Index digest:

sha256:0b15fd6d5972ba482c97148e55c0fb4131eaceafa38bcefe36c10d23b5aaa94d

Manifest digest:

sha256:db2f7327e70172e892a5095673684f20c0b545d2928a7cdf1a360564fd03286e

Size

169.43 MB

Last pushed

18 hours ago

Vulnerabilities

0
3
0
13
0

Support

Active until Sep 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:21-jdk-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:21-jdk-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:016c6817eba7aba8bc3ee71fc4c48fcdedddaaaa9ed919c8a5073744ab397185
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:b2d22750241825c73b0494d8ef980cb32340f3a31c6e1b8aa06890bbd507f736
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:6177014b81b35ea6bfcaf16cae78d760ed029bc01a023c3a213291456782c2ac
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:a8fb6024572465b8f70c28f632a533ce7427f8b8a8282526e92af96dcb85ce1b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:41bc6891358bc66f07bdb0a1e23d7c373627e90ea50506ce0cc2db612e2b0d23
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:43eb8fbf2bf6ab83383e56c9665d8a96fb6d7b32511c14f9a6c2cec2307032f4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:de6eab3b9509377cf6799da79dc85286da5c21a06d040438813d9a0bb99f289b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:84f2f823092cb1e3263536b19d8e819ea10ddc24661bbfa7146dcce234cb1f41
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:2cdbf700c995b0536c3f3a40244fe156f21a3a0779d1bf33bbb85b40a48d612b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:f153318bb4c776425b2e1085e7314bc1ec6e1013926a7aabde7e5fdffe05e3b7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:7efb35d81f290971731b32bb9d17840e0e2a551276dbdc5c98d686e95b505ea1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:26e03da1b50b2061d219a5745617d4de18b28212e2fb9a9ed528dca2c126f26d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:31d0fce574a90291ebe3c4b78de385b126a1a21b1615bd409dc8953013c25119
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:d501f6b0db3bae94de05f0e868c7385fe816c78c1d17a9ef3769d82af0a6aa05
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:07de9b4b2be271be8d1a6458da24c0bec5019fe4281a6f5ffdbc54d5107c0f66
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:d58263ab82b45abeb22789b0ea7aa9c42d5f2750a7ebf9cb3c6f6303e1c19974
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:502b8ee81a5e7382a058f7f65fad68c31c095111fd8ed29f9a150f09ab828b31