Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 25.x JDK (dev)

CIS
linux/amd64
debian 13
Tags:

25-jdk-debian-dev, 25-jdk-debian13-dev, 25-jdk-dev, 25.0-jdk-debian-dev, 25.0-jdk-debian13-dev, 25.0-jdk-dev, 25.0.4-jdk-debian-dev, 25.0.4-jdk-debian13-dev, 25.0.4-jdk-dev

Index digest:

sha256:990ab7b8bb601f8ed76bce09172824e831be0b11c6af0cb47c3104488a9b5150

Manifest digest:

sha256:5add3e2a77f5b8fd41710edc89fe4709cff76bd340aa62a5b09e5dd63f90fb28

Size

166.43 MB

Last pushed

12 days ago

Vulnerabilities

0
2
2
22
1

Support

Active until Sep 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:25-jdk-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:25-jdk-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:ffeb8f6e97b6d6eda4e606258a3ce837c22f8a1238388ab7c74a3a99c69d0009
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:811e55534ab19765bbe9eef9906b5892476b663829041ff785d265dc4a08d82e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:f8445c656d80304bd3f25381038fcbc42f949374f7e3214f14758e0ffe9106d4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:12473bf223367254ab3b1f08065aad52312af5816bdf8c32e650e9f1b6d960d5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:ade9e88d0ed21f13a04ed5731d6c898fa3bf07cade617840cf885f1743eea87f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:df3361df7d4dca0e1698bf0167b784b1700251bca34bd1d2bd85d99be9c5f50a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:8c6c9c3a6ba1d4c6ec593b9fb073a7f3bd0d2612505c425e88619af304445b59
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:d166fe3a18fbeecf84b7e1f946f7bd5d7e7e6f011ab0c53e0670f66bfd5edd6e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:d7da010de579bd662e2970e162377de80f4d386571163bd1bb2ff3285dc9fcc8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:2aa79e224aaf2394dd82e18204bf12df502a0a32546765c44b2d7dcc4c936b62
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:81e076f6c563cfed246c396f295109cd847b926d73c30dd1cce564eae310294f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:97294d526e89e18c0689dbd66ad1315e780a32ed7d4211a794f677f2515c15e9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:d4f132a2b08cefc3c20c95ba3cd403a49e997d374fcffbda8127fc52a6f8bb6d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:9ec79fdd6b80c23247d9e3001df0ba331f92535ce5aabc82a78335db32cefe4f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:1ff4b4a7b98be783d47ffdd0c28134c50d8d4ffae701066dc9bb4540e19b9cfa