Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 25.x JDK (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

25-jdk-debian-fips-dev, 25-jdk-debian13-fips-dev, 25-jdk-fips-dev, 25.0-jdk-debian-fips-dev, 25.0-jdk-debian13-fips-dev, 25.0-jdk-fips-dev, 25.0.4-jdk-debian-fips-dev, 25.0.4-jdk-debian13-fips-dev, 25.0.4-jdk-fips-dev

Index digest:

sha256:d15dd6deed369228fa24aa1ad0843d2faa91a88692e5269c2a0ca689eb65ed73

Manifest digest:

sha256:a94a0e76f4d441fc4d70bd7b4ce2ad1a56b278fffdc2a4eb3290618a19173833

Size

176.18 MB

Last pushed

12 hours ago

Vulnerabilities

0
2
0
14
0

Support

Active until Sep 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:25-jdk-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:25-jdk-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:cd27ab741c40cb82075da8e6d373c7d88de3878bf404e154114af53dfd3e07c2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:c079734f36a4acb2424e99845b24fc01ef3f6c648d4998c25f25cbc9cf760d5f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:24b02940a6b26ab19f34cd2fb3d441e705f4e3d4bd18bb6ce797554360bf91dc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:c0d0385b2e8e193184b3ad3b067955faad8b7dd43aa37dd2307a049d552907a8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:85428d8840950e60e39f93c7555ed22b100bd59cb0cc1c087d3c3f95283cfc08
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:73aa8c97fce812e4213656101ee29c745f44b7e1afb0f40b5847758db3399575
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:c0d2663b647df93292b707d649cfe98685384a70dc1ef53f2eb8358fff606c89
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:8f6a3ac5a2cbf81d59e292976d6f368ca7b0859a70fe86c25713a23af1797a07
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:278f1945c8ce0e6126547be62157e5d9cbfe950e047acee48d93a610f6f7f291
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:844ceaaeba89e35bbf1eadba99c5f66e731e38338766d701e6c8e211c166ef7e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:670011937afc593a9f077f65b3714668f543a6dcf7703f6aa4420825b4bc2b7a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:85f4f32d9fa7ee057f4c57f981b5cee8dabcd732bd88a1485b91a89b98940970
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:0a39752d5a20250c48e0e2d7690b82b4c23fbfdd33b21373cf8ab3e54164289b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:a0213f62bf76fb46df98bfa3b44403086d263e0a7365b5bd132b2c6dc9ce2e5a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:745d1a0b60263fafddeb76583bf74ef8743f882fc4844e9011f3cb8c73fb1071
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:c3878810b553f37983f0cb11783bae21ba0521060e9db5a73c6a2c7edd10bfa7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:f0e08d1f93adbf6600859b038700b36a300c527ae93bd39bf88fb037c757e434