Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 25.x JDK (dev)

CIS
linux/amd64
debian 13
Tags:

25-jdk-debian-dev, 25-jdk-debian13-dev, 25-jdk-dev, 25.0-jdk-debian-dev, 25.0-jdk-debian13-dev, 25.0-jdk-dev, 25.0.4-jdk-debian-dev, 25.0.4-jdk-debian13-dev, 25.0.4-jdk-dev

Index digest:

sha256:133ddc90bcdb93d295073b91b04100ab58f5cf72b5360dd6e05db7e913613d1f

Manifest digest:

sha256:870319741b0bb4f08d79a6ef68cd8fd2c41084a551e47b3dd7d9b2d06978ff10

Size

166.43 MB

Last pushed

17 hours ago

Vulnerabilities

0
2
0
15
0

Support

Active until Sep 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:25-jdk-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:25-jdk-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:52c6db43faa6456f96ae33a4b32d7d0304db62a5e6c4913e8cfcf10326d8c4a6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:034608a7abdf729bf9bf46aaf3c70df56e7fac64222f96f0daaed31a31884919
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:68f97369aea332ad4c23bf752d2c3efa354997cd01c8f912888a8c343e0f6e21
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:664d09d3b8084346f597240cf0d80b2c71d48773ea935ec486c7c0308f405453
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:26561b2bd9277182634ad78bf55b09e822f45c79e1cec9f572912796b28ed88e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:6087c97e02d46c4fa26c16af8c3b980d508346814d59b9b782f8761ef153efcb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:0d379b834f2d12c319ea6f4048c6159e6d6bd8465ea0d03da6aa6ff5fb1f9354
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:de75ad0b9c3a335034b98955a2e4c50bc376c8aacfe43b4ecf002a4673508c68
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:ab80855857ecf77ee28cc2fc39e004f91c82817757cfd5bc22746149a5fa1bb0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:aa73ba2c4a45c5e965b35df2d015cb6f6da887b1ce5869b1e66a5914b0054d0f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:4294dc961969e71daf6aa09d933d0c062a801d2942353649bb7ec16af0123d4d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:ccbcd35274eca21b9ce1a8dd3358e636153f7b4fdd8389c54a9744377bae5b9b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:3c0fa3d69c68073f57e95f6e698de3f088b6f47d6e622fd355817252e838430a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:d41fcc28b3a24c044521f9cc6c69bc912f92f8727cf11265d300bce3809dad18
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:7e772a5f5622fba1e01d39f689b34ab0761a0a49e50fc517c9b7534c7150471f