Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 25.x JDK (dev)

CIS
linux/amd64
debian 13
Tags:

25-jdk-debian-dev, 25-jdk-debian13-dev, 25-jdk-dev, 25.0-jdk-debian-dev, 25.0-jdk-debian13-dev, 25.0-jdk-dev, 25.0.4-jdk-debian-dev, 25.0.4-jdk-debian13-dev, 25.0.4-jdk-dev

Index digest:

sha256:3a3b5e809c60375850d6dc66df15ac13af570d81b6c7eed26570e02c3a52931f

Manifest digest:

sha256:5add3e2a77f5b8fd41710edc89fe4709cff76bd340aa62a5b09e5dd63f90fb28

Size

166.43 MB

Last pushed

19 hours ago

Vulnerabilities

0
1
0
13
0

Support

Active until Sep 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:25-jdk-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:25-jdk-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:ffeb8f6e97b6d6eda4e606258a3ce837c22f8a1238388ab7c74a3a99c69d0009
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:94e1ef259d5d2739156f981ed14f186dff84df2945fbc634783f2257d915aad4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:623c2bfe1efa27cf4a6e5190902a91228d43a2e2ab306f3c1ea9089f4130671e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:f4e4dd32f9f44809f4a53bd0c567b4db8027ad2503e783f784b4828debf33244
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:819a90a1e07f37428735ad1d629192b3c791fe9813ca97ca7d4757659ff5504f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:df3361df7d4dca0e1698bf0167b784b1700251bca34bd1d2bd85d99be9c5f50a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:b50a534d7931eef7932305f1efad7a0b0f5efe74d22a162618c1da821d15775e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:d166fe3a18fbeecf84b7e1f946f7bd5d7e7e6f011ab0c53e0670f66bfd5edd6e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:2ec759a8f32bbf15030a7153dd12cc3b667142efe9d3b354945a1ff05b726243
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:f8430d348d02ddea9b8650d455775e14d0cb9aad7a0b43630469118c0c01beca
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:c21d9e6f713d81ae38069ffa97ea753880c8ae2b23de7d6cb559628bd42e3af9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:97294d526e89e18c0689dbd66ad1315e780a32ed7d4211a794f677f2515c15e9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:d4f132a2b08cefc3c20c95ba3cd403a49e997d374fcffbda8127fc52a6f8bb6d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:4668f766d0719748052c64a5c4abeef0515cb19aa8197cf30f8f8354661f9780
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:1ff4b4a7b98be783d47ffdd0c28134c50d8d4ffae701066dc9bb4540e19b9cfa