Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 25.x JDK (dev)

CIS
linux/amd64
debian 13
Tags:

25-jdk-debian-dev, 25-jdk-debian13-dev, 25-jdk-dev, 25.0-jdk-debian-dev, 25.0-jdk-debian13-dev, 25.0-jdk-dev, 25.0.4-jdk-debian-dev, 25.0.4-jdk-debian13-dev, 25.0.4-jdk-dev

Index digest:

sha256:4f75009896ecf60e22f31cfc5b87cf1a7a3e77a427dc653b99d9870ebfe27e82

Manifest digest:

sha256:ff0a5e7c4373b4caec641f289e38e1004ad6bfc15240abfa61a57b7f0aaa958e

Size

166.44 MB

Last pushed

11 hours ago

Vulnerabilities

0
1
0
13
0

Support

Active until Sep 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:25-jdk-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:25-jdk-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:a075020b46dd4df2a224c9bfd22eb1acbb0622c6956dcb76e9247a7100895e88
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:7dc324b250d3281e5ce034b533334b4860419a7f3e7825cdc6c101331154551d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:c80a58e2ecfeb211a4f583d441e79d0803e8d6567ac6b993d47cf4c81a3d71eb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:dd1c7fa1021300b94c3da11b36a21833a51e9efe7e4b9308fea07294a44d2bd7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:208e202777a0f4774d72890f4798d432754f0ffce232619cc900de1ae169f166
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:3278de0a35300d689fa3e111c5f9d289f54d1573ac4f03f9660284d5eb148c34
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:31123f3949f015aa7eb6ca3f55828d821b91828279f7767acc848fbe00c48b9b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:e720679d4d42252afe68f24d6db1a0439775ac178133885e216e3c7e353a73b0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:44137693727ac6f69ae31125e073037698258ce19465ed7d87b0fa5e82269b67
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:3fe73ecfd730a975f5358231d4cdce33dd1d5dd1b45cd1a8802a173b6b140e89
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:e1ca33e94a34b2653510abaa6bda984359c4a2c5dd7131217421529fb8acf788
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:ff521fd1b45737385ae03d806e3a0435072d43bdf3b801536d528f95bcac271a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:8bc8d5620e042e5563d059542f5c9dce07401a704a1338332621c279455a07a6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:f7e95e094734bd042bd4d36f1fa7f94dc71f3346dcea04af8cf3a948044349f8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:3180b806a21f07a58469b23bece36643e20bb970bf4897acf66e74a78bec3117