Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 17.x JRE (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

17-debian-fips, 17-debian13-fips, 17-fips, 17.0-debian-fips, 17.0-debian13-fips, 17.0-fips, 17.0.20-debian-fips, 17.0.20-debian13-fips, 17.0.20-fips

Index digest:

sha256:57a0427d036a81cadb113144bfdd82c876688b3303aa6b37a7e7f436694828b1

Manifest digest:

sha256:6aa251d64c1b812d90b516c4e61368532e546cc322b8a791432d5b2e46cfa348

Size

74.40 MB

Last pushed

10 hours ago

Vulnerabilities

1
2
0
12
0

Support

Ends Sep 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:17-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:17-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:f4233df25b5202f21855e8430e4060bb82aaf6407e35a2e7f0c516d8bc733e58
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:9960bfb20ee5a42b15eb824f66b253d9928fe979e406c5aace554f3d037bef76
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:7e57f578bf8e808497d6ab21e6fd32b85d7f536891aa42ee551647e863df7413
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:23a42381b75d8f6ba632896c204673baf4f5bd18db3b1acaa8c6bae258cf1278
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:2f43816cd0587ff1e9f9d744e0f8a45b0041ea1187909781218707df3abafce2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:655cda6b36461691bdbe0bee42a3d061542d26aff5c5f7da99a13e364f3304f4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:4dbf1457271e43a8814fb1cda839fd49df3215dfb016603823714f19eac221d7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:70c7465b7062bdd9d2fe209ac3586b59090e3c181d5bc4996cd303c85a1b86f5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:5b059ac2ebee2a9c49109a954ad48208f4ebf729833f7d4dc1a6151cf6a3261b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:7751efefe28683d05d60a098ea70f911bbe696ceb68a62e53747b24a3af6ca05
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:27751a06d3ea813f787cbf9f2655db6a9f9375d10a18c46b61e19ec3e0a29984
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:1b2a4f9c0ba2054351e79cb450b19d9d49029e1ed02b85325b39be66e46aacd2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:aa53c9482fb13202e06492bd30d4c50510bdeda07fd3c29ee61524fd76b54d28
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:ad14844a065547c1d199289f5fb99f19cab25995fc0ad2b2042af43101d95a8f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:4a7c0d6f81ed48d1209193d1c1a31846d3530218492c975c232024b093d64688
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:a1a2b6878ffc9f41cd9a44fa451712651310e6b9d8575e237c6530e2ff3fc717
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:4f90e496e06eb04cea5680da476447f3792da75b653debbc8a64cbc16790f6c2