dhi.io/sapmachine
26-jdk-debian-fips-dev, 26-jdk-debian13-fips-dev, 26-jdk-fips-dev, 26.0-jdk-debian-fips-dev, 26.0-jdk-debian13-fips-dev, 26.0-jdk-fips-dev, 26.0.2-jdk-debian-fips-dev, 26.0.2-jdk-debian13-fips-dev, 26.0.2-jdk-fips-dev
sha256:f3e361da5c8d16324c2da078f6a20fb1a813da04c4c51af4a398f4da7374b010
Manifest digest:sha256:6b2bbc2fbc3016cd09b4e268254b95c2391f1fe9a6b8ff7be5409470f224db32
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/sapmachine:26-jdk-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/sapmachine:26-jdk-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/sapmachine@sha256:d94cd46c5d3bd4710db42b7fdb4ed57514290212307decbf93e265c8b0429f54 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/sapmachine@sha256:70adf1f7f92cb7361987418516b5d62d4fdcda7a1dd0802cab7c922bbe5351c3 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/sapmachine@sha256:02b6e21a19f4ac9bd9d1118e8a1ef90107360aa7aed65b21ac6a63ed69eec54f |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/sapmachine@sha256:eaaf2ad889d8a1f5950bac3428102ca11e92b17c7875609d42e715d529f9d3dc |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/sapmachine@sha256:de7624b2aeb8f530599cbabed3253e6d3443993f8dee256126cd396bbfe72dec |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/sapmachine@sha256:e9b82e41caa5dc5fcbd4e8ac59c3c3ce17d026517327758027066f5bebe1c3dd |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/sapmachine@sha256:10d4d6c4f5931e4f31e583250b3f3395d9586b22fb08bf56c4830c0f199820e1 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/sapmachine@sha256:20e27b6cb9df38eea00ea98cc43bb2b343e5fe3d40d0352f152751e9d5cc9a3c |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/sapmachine@sha256:3d40db4114e2043ee7cf3838c46f6d2fab98a52d2503b5c452b9608a6e464229 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/sapmachine@sha256:5a762f7e24dfdf76d8a57be9573e8f06c100b3708caf993c9e6790d2e26b1074 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/sapmachine@sha256:9096ef5aedb97f8928d2e6388ce79ad5850783b7101c682cfed877c29ea4f39b |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/sapmachine@sha256:5a48165486d3ebae077c4cf0ca4d75c4cc58e916cae9b55ad25dc636ece688ae |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/sapmachine@sha256:c7b754a490a5aeb7cf733898ee5da6e4af146d381b3ef41ca936e4114c9899d7 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/sapmachine@sha256:b09378ed95783fbcbe3f0a7f1744fe094f641a76804bfa4c95335c169f77c17d |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/sapmachine@sha256:65892fcf9e8a190a36014d4fd5d8da9ea893177b4aaa793cc343e1bf3730c8e6 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/sapmachine@sha256:c744f464ef0a036ebca51106afbf44d01de4bcb997147bdb7887b9e34e5df715 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/sapmachine@sha256:218bdcfa782dcd4840a45de215bc95fe8b949b71b24f7a39f1fc100f1607008f |