Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 26.x JDK (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

26-jdk-debian-fips-dev, 26-jdk-debian13-fips-dev, 26-jdk-fips-dev, 26.0-jdk-debian-fips-dev, 26.0-jdk-debian13-fips-dev, 26.0-jdk-fips-dev, 26.0.2-jdk-debian-fips-dev, 26.0.2-jdk-debian13-fips-dev, 26.0.2-jdk-fips-dev

Index digest:

sha256:f3e361da5c8d16324c2da078f6a20fb1a813da04c4c51af4a398f4da7374b010

Manifest digest:

sha256:6b2bbc2fbc3016cd09b4e268254b95c2391f1fe9a6b8ff7be5409470f224db32

Size

95.93 MB

Last pushed

13 hours ago

Vulnerabilities

0
3
0
13
0

Support

Ends Sep 2026

Request ELS⁠

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:26-jdk-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:26-jdk-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:d94cd46c5d3bd4710db42b7fdb4ed57514290212307decbf93e265c8b0429f54
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:70adf1f7f92cb7361987418516b5d62d4fdcda7a1dd0802cab7c922bbe5351c3
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:02b6e21a19f4ac9bd9d1118e8a1ef90107360aa7aed65b21ac6a63ed69eec54f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:eaaf2ad889d8a1f5950bac3428102ca11e92b17c7875609d42e715d529f9d3dc
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:de7624b2aeb8f530599cbabed3253e6d3443993f8dee256126cd396bbfe72dec
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:e9b82e41caa5dc5fcbd4e8ac59c3c3ce17d026517327758027066f5bebe1c3dd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:10d4d6c4f5931e4f31e583250b3f3395d9586b22fb08bf56c4830c0f199820e1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:20e27b6cb9df38eea00ea98cc43bb2b343e5fe3d40d0352f152751e9d5cc9a3c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:3d40db4114e2043ee7cf3838c46f6d2fab98a52d2503b5c452b9608a6e464229
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:5a762f7e24dfdf76d8a57be9573e8f06c100b3708caf993c9e6790d2e26b1074
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:9096ef5aedb97f8928d2e6388ce79ad5850783b7101c682cfed877c29ea4f39b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:5a48165486d3ebae077c4cf0ca4d75c4cc58e916cae9b55ad25dc636ece688ae
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:c7b754a490a5aeb7cf733898ee5da6e4af146d381b3ef41ca936e4114c9899d7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:b09378ed95783fbcbe3f0a7f1744fe094f641a76804bfa4c95335c169f77c17d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:65892fcf9e8a190a36014d4fd5d8da9ea893177b4aaa793cc343e1bf3730c8e6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:c744f464ef0a036ebca51106afbf44d01de4bcb997147bdb7887b9e34e5df715
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:218bdcfa782dcd4840a45de215bc95fe8b949b71b24f7a39f1fc100f1607008f