Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 25.x JDK (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

25-jdk-debian-fips-dev, 25-jdk-debian13-fips-dev, 25-jdk-fips-dev, 25.0-jdk-debian-fips-dev, 25.0-jdk-debian13-fips-dev, 25.0-jdk-fips-dev, 25.0.4-jdk-debian-fips-dev, 25.0.4-jdk-debian13-fips-dev, 25.0.4-jdk-fips-dev

Index digest:

sha256:875024f813578453269c6752073909868ec939837fc8b7930f121e7ff7236f12

Manifest digest:

sha256:fdb77a7ecd4bd8991e265cd4c9bcf406633be71d2f42fb37342d0525168ea54b

Size

182.96 MB

Last pushed

20 hours ago

Vulnerabilities

1
2
0
14
0

Support

Active until Sep 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:25-jdk-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:25-jdk-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:4f1a2c8de54bc85a652ca6a28d6b83db17de24226b56d796a7014c6aa5db0002
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:f073dc7a6a31f1fa3b6d405dfdfc81e050af8fb856a006a17f3bf8d961459a8c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:e127212a446853fd39eb89ee22b4773d450e9b2357401fd15b743361de8c337e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:03aa0fbfa2e697f19feffd531d9ec49443ef05dfcffafefe6b4d5b86ae91b5c7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:330d48ab1dcd0f7e9006e53a300c6ff9e6bc50b7cec66b68784c13870bbab782
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:dbcd414a174d4a06fcb17e2aaeb3841c78540755ce90dff1677532d00df0264a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:46e1810611170308359e9456279d189069c0738f18c4b37b2c2d2dda0c8b6332
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:94e6bf6cfd72aa091287be24c9f4f875711190cf05cbd6a8268956ee8eb60bfd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:6cce7a52b90c57a91b28d6014f9ce2b39448d693cfad736710e5bc503ade7719
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:86002dbdbb4989ee2f58483d006e5f0c75980e8a0d7ad5a58bf5f53bfe9b97cc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:1d61e87ea065b0b6cf79a44a3cad015841ad5f0dcd4eeae4592a7c00e5f18cbb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:b95cc09ee6df4d09fd2b03fcaf9fac67e40cedbd41c20eb30bf78e096fd54a7b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:d331b8e6814e9c484b1bb110e52d6e61c78f6aeee7f3e80514ccb9de4207fd54
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:f2850009cac7ee741ee50faa7a37a67fb2325753a8d013de8274baa1b686cf47
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:1f9186b995adad3072e4febd980f5e000cd8138bae9958bd4263ea26fb767263
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:12ee3b78b21db7f2588e8dfe55f3ab473a5a5d05017b9f34d2a5e4f8d9749815
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:b72980dcd800cce0e560aabbb25038331ae02547aa3e896e6cc3534f0db604ad