Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 25.x JDK (dev)

CIS
linux/amd64
debian 13
Tags:

25-jdk-debian-dev, 25-jdk-debian13-dev, 25-jdk-dev, 25.0-jdk-debian-dev, 25.0-jdk-debian13-dev, 25.0-jdk-dev, 25.0.4-jdk-debian-dev, 25.0.4-jdk-debian13-dev, 25.0.4-jdk-dev

Index digest:

sha256:f170b3b5b97a4d9240573e526be9fb600689bab673dac3ebbfb2db4e23872ca3

Manifest digest:

sha256:994e02c8df33149b8da0148a09ab56731e7c4b366c0f322007d8600b3b8fb9de

Size

166.44 MB

Last pushed

22 hours ago

Vulnerabilities

0
2
0
14
0

Support

Active until Sep 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:25-jdk-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:25-jdk-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:1be9a8cc8bbe0bd265c09e4692a4d2fefb7b152d4af739cc26396ad7b3ec3e48
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:d491861c75f7e3d0c002c0274022235315a69b141652b9937ca934f9284311af
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:05be4599114ba03760845fd03e6c85c79ad47199391f17305877daaa788fe43f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:1b1f63ae63517beaa8e259023e3a8455812553ee76e4c9f404c77cc517945ec5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:aa6c00274e368f7e419ee7332c2969d83b5dfe22c62df95374eb826ca0e9209e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:fe72f43d04d5e1a8cd84765261f68e8f6ace2b973600c4a56f01766ee2f8d3f1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:817bbf62cc6d280595b51863ffbac8c2a74a9254fde561dbf5c4e58157f7bf9e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:cbe13b3ded9b12b7ad34305e3dc6db228d01b26891a7a2d81638ecfbeaca4321
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:05748e139063e826dbc6dd807642c72bef60ccad7f34e8a74f8bbd67045721b8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:2679d57cc34a63f4a9ec959c178d7bb6176a92e837a348ba75602adedd4298b7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:d38e6024394c6a605084729ffdcd84a9f78d7b54892ae3dc4d1d1eb048b5ef8b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:219e196afe7afd4fabe83d1e9e80da31c3cca99ea8fa01ba001014e637b59454
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:9dfc309485b970df9dcf0c886dadf61ea0883eacfdfc447e04bfc2a5fecb4b1b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:164d62d557a1aab1d84120beb6211296a27a7c4653732cb42d9fec8c879779b7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:505263940304ef8d3e89498c845e0df0f251513b5f4279e0fbce565fc9e20a69