Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 25.x JDK (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

25-jdk-debian-fips-dev, 25-jdk-debian13-fips-dev, 25-jdk-fips-dev, 25.0-jdk-debian-fips-dev, 25.0-jdk-debian13-fips-dev, 25.0-jdk-fips-dev, 25.0.4-jdk-debian-fips-dev, 25.0.4-jdk-debian13-fips-dev, 25.0.4-jdk-fips-dev

Index digest:

sha256:5f93ad08e49898ea74fbb49501a6a647e6fdff28547381e59cee439e9c17fd1b

Manifest digest:

sha256:11f24494e4af7309511b9c447758d9b4467d8d4f3a5cc4ba418e58f78dd464d6

Size

176.18 MB

Last pushed

14 hours ago

Vulnerabilities

0
1
0
6
0

Support

Active until Sep 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:25-jdk-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:25-jdk-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:363d86c95e18bc76c10e7e05607fe3a2b21115d58c7fb1777d498b9d937236e5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:b3e78decc46a080422b6f78906704df70381639015ffc31c0d1bb3c41da16c92
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:d4bf1c200212dc4fdcb24c0e118686547753eab4e6ebef14fe0c8a112ee9e652
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:4f2039a5ba1267ccb489335792eb198f995dc10051219376d897dfe1366d222f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:cc4bda1780a994ea6a28947a23ec55d63dc738d4464c7470fb4434d21352f3b6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:e25db09b56695b437bc9e968898867cf8f4c5b5d9ba5c34532a287cc8189833e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:5c2fd1c08056111cdfc82229acb900ed9e19a8e034255cac233f2facf3852555
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:8060d3f0c89ddb093b66a8ee6e811c1418846d9bc9441a506055dd54c3e1306d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:99a865a77d53f997b4a296f67464c1a5f661cfb44487f701829940a73290b992
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:285d7672d4c215b5c2f4f119277b33450ece83b1ff335ed20521945851eb1576
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:7edfe564bd77399b1276dae6ea3d0604bb05f206cdd51801d897274d3bd03b85
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:1d9d5834303f8f1b4dd5baf17fe7e5e0a913a7fc36a3edd6ddee9a8abc81cd9f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:618d1d2c32e1559ad9fb6e7529ff0a7e3bdcaca306283e6e301d692163574e12
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:37af99fdd426e559059c9ce0d0b5a8c12090728d72d8b66b43d653ac508ee2e8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:b65512646e3b6d409e5d7bd0b8ece8433f485e765627dfc7afdfb9bc38fc7680
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:f35e21a5f901c3c7985b8631e693b346395994c8326fe067ee40e7a7d3cbe934
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:70c5a563720a6eb166c6594b35b17e855c21b51362719f98a02bf251f3dbcd2b