Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 25.x JDK (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

25-jdk-debian-fips-dev, 25-jdk-debian13-fips-dev, 25-jdk-fips-dev, 25.0-jdk-debian-fips-dev, 25.0-jdk-debian13-fips-dev, 25.0-jdk-fips-dev, 25.0.4-jdk-debian-fips-dev, 25.0.4-jdk-debian13-fips-dev, 25.0.4-jdk-fips-dev

Index digest:

sha256:b75e5ad74224885bf851191b556a655fc6785ed31c0c7018482f607f1e3ea2f7

Manifest digest:

sha256:b7c7dca67c02dfe5a288a64bf7e4fea23a212f4226a8963358cdc0f739c622e5

Size

176.18 MB

Last pushed

3 days ago

Vulnerabilities

0
3
0
13
0

Support

Active until Sep 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:25-jdk-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:25-jdk-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:a4ee42f9d3adaa0952ebc589cdd0ed6bdfb3a96728bbe348a9c1a516faca8b4c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:17a89b8ee272c7b261dd607fed92e6186dd4f3c6702b9695d80f716ac94c617d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:6a10fdbdc6a81bfcd71f16227cdd8a462c9999f5ed11bf01db9318039bc56852
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:e7ae704a34953042d5d31593489b2ec4d70290ed949aa765a2f5b156c1187b90
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:01b50ecc263dbbe0e66fe409a79d17fd487745417dfa0b4f86436fe262c77e81
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:3747bb62bee4a7fef1c260aaaf01fcbd1b822bc960efada25d89622ede5515ab
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:9f577e410cf8484aabc69ea757d7d7d0d3e53c960793e9efc479b1b47be56503
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:f3cef84ac43ba461b422dca06eff29e43ff5a51705ae4ec2274977e23c4c100c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:4aa8ce8c0049dc6fecff5124bc03a8f7ac01f1e1e8f53e6febacdaa10c0a653e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:f7ae553a96c1ab5ce8426667f7d9b7122e48671e41460a50edb8e2e13e652a29
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:fa38388542a5c08b68839cb0af30570aac78a5735ae2159582897efef2dfc659
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:77f0fa7b3ea2156967a67d065b2b2045b59759506da6af421d706f638935c574
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:57b9c820eb6dad88097bf073696cd12d638ef0d98faa544a7825e3f3d095aa19
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:d3fb22c93afc592cfd638ca9278f90517fcfad97c432116bb0c61716b6454e1b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:c0da0d656f96d86126ef62efd4f671ed1b4ec708c570deb356036c4961feebe9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:7f7f3e1392e16cca13fad729976f14eb86db148c8def36b6da6319afaf57abea
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:c47f5622a0dfcd3bca598ce9826d55edc4d0a882ab9e36297e3b99e324c745fb