Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 25.x JRE (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

25-debian-fips, 25-debian13-fips, 25-fips, 25.0-debian-fips, 25.0-debian13-fips, 25.0-fips, 25.0.4-debian-fips, 25.0.4-debian13-fips, 25.0.4-fips

Index digest:

sha256:912b3df7c4b6937e78fa967a34e6cfbd8f4b2c99f55c293fe821700bae06718e

Manifest digest:

sha256:e369482fb75ddafe2de68b4bc9bd9ce3ad4d342e9fc76e8db8e72d1feca9381a

Size

69.02 MB

Last pushed

2 days ago

Vulnerabilities

0
2
2
20
1

Support

Active until Sep 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:25-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:25-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:6d0ae4200cc36aeecf22564603a5ed7a96e6335e447e89d741a21474270bf447
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:ab4d52231c3c14ec8f8e43645ccb167eda9b4b4df9224a20b5979a1054e2350d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:6ff42f0d0c5794a9e32c95258e74414acd3a4532b83ba5cf536441078542b326
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:64965893d2ff3365953fe571491faead98fa58daeed6420c65e936009333e14a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:83ec0445b993cc1d5c73ded6efcf61262ebdc2bd510ca532a573979b548ebda3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:d40deaf70c78f0904942666ba88ecd4425abe220feb0ff8e24397ea29f17ab8f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:3ba08b77a5591d7956f325d0142f9803a01b1e75667143b726409c890478d26e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:7e43cf36c4175bfc15340b67944e7793ea3e0012a893f67dcb7d2cb67cc154b7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:5d6ad195dadcf918c662fcd22550943cc5ab643389b14ac7ef5ba8409fccc6d1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:53cadabbcc88b2a272b60ab748b78ba88f5155774f6cf7f7773a3da04b3ed047
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:41b7c9b959e6a8f80c1105ad14e60d06547f551b5b75b9f2c3695888bd91d672
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:e5c6a7920924625de243cf783a83c2c070e9f7eb159b1d5c6931b6ce5fef8918
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:7828b90cfca3498d3930d17249a3372a6c68351f7122bd939b41d17e99de107b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:aa46adc24694e819a1d0d2b8c6444b580f1164d0c9004a4665a9d3a95312de37
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:e0b34915372b8524005bbe077ade206a0969c0222ae677867b2f2bb4f3a25524
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:78a49a0638e5405ebf0c6e57052f864b0d6a6e22c98662b1ab1a80f3c55fb36c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:7206e38918c51ab75486719b7d10430179f23e1ff5d1d73af87278f3e79c048e