Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 25.x JDK (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

25-jdk-debian-fips-dev, 25-jdk-debian13-fips-dev, 25-jdk-fips-dev, 25.0-jdk-debian-fips-dev, 25.0-jdk-debian13-fips-dev, 25.0-jdk-fips-dev, 25.0.4-jdk-debian-fips-dev, 25.0.4-jdk-debian13-fips-dev, 25.0.4-jdk-fips-dev

Index digest:

sha256:e315967d91b444c9f93648a20291323650580369feba5722cff875655c567be9

Manifest digest:

sha256:03595fdfc75ce53191f93ff67363949d48ddb56ccee0422baf0faeed53def35c

Size

176.17 MB

Last pushed

4 days ago

Vulnerabilities

0
5
3
22
0

Support

Active until Sep 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:25-jdk-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:25-jdk-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:853b926facc86d08c91f330e37e6f5d259f4c7c2b75a6ee02fa511fbc72a6f6a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:296db01217429009016a3b88c839452b6a40faf5fef8bfe3cd8c5732889cbc60
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:df30b31bf7b5b16f7a85e89e190fd29768db1f461923e101830dc270ad22dd86
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:64b2d17bcf4ca63cc181890670a86df52c4ca70add4a853961f2425168d66381
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:4e4c6799edb1700535d0aa898c4e530db272bb472769242ca837ea93c7e2595d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:5261b05b600cc8c2e6824efd4025484345dfd0395e96f98a5f0a9167fbcd36f3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:3a4e67d3b320fc6b2adb94d063d1aa4db382a7c15633e9ff4fabab6adc295866
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:7a3c244b86601cf5d5efc979ba0ec7cb60518010c30ba9a189d0aad1ead15de5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:0968d11e4347008dc3a507d10865cea8bf6c4676bd823cd40c53f88fd2ed2fa5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:2f1b02b90831a1aa5d550182736f4c7c41137b123a2db4fc1021705a1d156507
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:f5dca374e0776b7956830619a195132ba32123538a4432af5da94609ba647edc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:4eeb1761f1a0518b6b4df48f168ac67bfc830597f8ec553430db8e8f7a86bc35
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:338d78b6f58d1da9b883b6a4a60129cbcb99caffcb3f09201fe2fb36776c2c0f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:cd92ad6c8734950685feedce29566860194defbf9f567bf9079da16dd38469aa
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:43e126de174432db012e5e01331af8439c168c055a6ee51977da2a0b6406b9d6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:aea94e3f8a91e85d05e20ca9b309570c1b2711de0f0f800260e7077ca9185606
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:33478090785a5a534b38a21ef1ec92a65af08c3f0a08467d5fabb582cb808cb0