Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 25.x JRE

CIS
linux/amd64
debian 13
Tags:

25, 25-debian, 25-debian13, 25.0, 25.0-debian, 25.0-debian13, 25.0.4, 25.0.4-debian, 25.0.4-debian13

Index digest:

sha256:a40cf5ba3f560b23c69f688800da5d4a6245960d5322f790e75bf7ea8c18beac

Manifest digest:

sha256:42c780be8057cc2b14f2fd5bef98d7d05d703952e98e603cad03c30fbd52c8e9

Size

55.46 MB

Last pushed

15 days ago

Vulnerabilities

0
3
0
11
0

Support

Active until Sep 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:25

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:25 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:92deac5968f7f7c2e6775db732b6ba80978b39c968052d62c27ec173b05a0915
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:974abcee6b0f16f8293fb6ed443e3b55949d9f6716c88f8cb6d0f958441e8291
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:de9ba91ec70e44b52504434a726db691f8db8c6abb6772b5fce79730aac3b68c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:3286314adfa6a7c6f989970b7aed6de35f98da6c9ba6d034038eb98874a8b17b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:8f63ce91924d9caa51b5528c41ba4fdf7a6659b5e5d5d96848b9367d9bae20ae
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:9e894e6a5f8b7dbed5f6b208ab2a12b184e12d775f9a30d0ee5b6369df980499
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:ed67b88e62ed5a543a7789be52a6ebb8cf27407c5ce6c393cf210aca9a4f6bd8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:c4922fc9ce4671983ab6df0a4747d0e9cb8833e9db6d7eba738f3b6f57163d8d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:aade3b5c62e2e9cc3e08d04a3bd56c0292836d37053978f6d1f2f3f30dbac0bb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:479f16823b6217645edf2e20aa252bbbff98598aa243dc7ca62c05145aa1f8ec
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:925dff8af65085c7d3dd95f42ace8af275f1fca4318b70c517108a275bdbe01c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:baf23e00d6017d35f06d9234ca516128e50c738139e3f391f5423c7744b2ed67
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:26a20a391159a625addc35f50f0a4496ffd63b6690ae4d19f87da820cc8f33d9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:29bf36d04edea6c8a97156231a90a01dc6acea9fdc99bb506fe13f2f0a3852a9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:6c3490aad7b2eea6c4f682d3502f72279f1059b56ee320316bb7a1320d1c688a