Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 21.x JRE

CIS
linux/amd64
debian 13
Tags:

21, 21-debian, 21-debian13, 21.0, 21.0-debian, 21.0-debian13, 21.0.12, 21.0.12-debian, 21.0.12-debian13

Index digest:

sha256:a609b0e753c8c7da690424b3cdb1e20860c2f843f0cbb81ee06d69fc07073ae3

Manifest digest:

sha256:5d9e965f47aee9b9232868dbac179e60d9ea546c78dce9e1cb43513d8c4a7f5e

Size

57.80 MB

Last pushed

18 days ago

Vulnerabilities

0
3
0
11
0

Support

Active until Sep 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:21

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:21 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:bdf3fc5bf9acdba230e7b9bd4332a305ba8aed70fea8ab8ef52c4d048a0d02f6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:80bc4eaeab5885843ffdad308be2ca5650a0abaff8532b2d3cb090fda934ded0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:bbe8412d06ba6ac51adfeab383ba7e8c8fff43f94b21c7a93c7eadf96b16d81f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:09b37552212617de55ffc4c131866511e19f03be8d30883ab11dcc0ecf7d199f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:c4a53b8571269d0c41d410cc8667dfa7b577a912b16bedcd9631e1b6a264bb34
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:a3ee4d0950ea2ed96217080cd5d8536f94e70374740bb1de8d5e70581d7d700e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:0aab9b3fff2c0e127a4042493215d01d23ce09670809e1fe5a663a71bcc5d496
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:d965ceec04f204eef2801571aa925867c681c6d24fd39dfc34a9ece69f66719f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:554ffde23ebf341d6fcb54305d3f5f64421a442c260c06cce6dc0a2cd0ed4ca8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:a69d9122088fdd3c54be4cbf173a1a9d0133a105667af9e4cdc65c535032463f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:306394909d700c2f68d2945e430250c33ab21ae47cf20d3818f15201977bbfe6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:505283b0db38e118d607afa341e2c3f83c896e892dd7d6353f081fef5ec78aa1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:4d4dcf7d1df12ef7361b17a4e68756d549f9bba6633733fdb33c5749f452732c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:3d0e4c9d124b7e839a1afa3e826b345f5e77238ca391658e6ef4b6cd84f8dfc9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:d1008b8dffe6c30ca113a3cec432e60bae75b95085cc23aeff39d73cc756005c