Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 25.x JDK (dev)

CIS
linux/amd64
debian 13
Tags:

25-jdk-debian-dev, 25-jdk-debian13-dev, 25-jdk-dev, 25.0-jdk-debian-dev, 25.0-jdk-debian13-dev, 25.0-jdk-dev, 25.0.4-jdk-debian-dev, 25.0.4-jdk-debian13-dev, 25.0.4-jdk-dev

Index digest:

sha256:f170b3b5b97a4d9240573e526be9fb600689bab673dac3ebbfb2db4e23872ca3

Manifest digest:

sha256:994e02c8df33149b8da0148a09ab56731e7c4b366c0f322007d8600b3b8fb9de

Size

166.44 MB

Last pushed

9 hours ago

Vulnerabilities

0
2
0
14
0

Support

Active until Sep 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:25-jdk-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:25-jdk-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:1be9a8cc8bbe0bd265c09e4692a4d2fefb7b152d4af739cc26396ad7b3ec3e48
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:b91aa88690921f5f852f77c64dc7585db2372cd190bbb718feb3398b3e016beb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:068863af55ca8966cddf888acf52d0d841afd41950227cbfb5dec2f7fd661133
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:ae70b18e445daa8fdc1e41dba0a20cf31511e99b6a0699288fb91891a9244698
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:a0ea0b614995d06a135fbc186bb71197c8b4c6444f260dd18d71abb13f28c817
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:fe72f43d04d5e1a8cd84765261f68e8f6ace2b973600c4a56f01766ee2f8d3f1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:817bbf62cc6d280595b51863ffbac8c2a74a9254fde561dbf5c4e58157f7bf9e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:cbe13b3ded9b12b7ad34305e3dc6db228d01b26891a7a2d81638ecfbeaca4321
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:90bd0456c291376c72ed91418893451d12a82916515d9ce80272e171d06a6368
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:6ecdd6885f091e419939091dd322520c1f2e34b96f9f335e1065bb63feb6b0d1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:f261f56cd61d2fe2bff59cfa88164ded371d208c9e7b4836a1609608bbdf4d97
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:219e196afe7afd4fabe83d1e9e80da31c3cca99ea8fa01ba001014e637b59454
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:9dfc309485b970df9dcf0c886dadf61ea0883eacfdfc447e04bfc2a5fecb4b1b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:164d62d557a1aab1d84120beb6211296a27a7c4653732cb42d9fec8c879779b7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:505263940304ef8d3e89498c845e0df0f251513b5f4279e0fbce565fc9e20a69