Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 17.x JRE (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

17-debian-fips, 17-debian13-fips, 17-fips, 17.0-debian-fips, 17.0-debian13-fips, 17.0-fips, 17.0.20-debian-fips, 17.0.20-debian13-fips, 17.0.20-fips

Index digest:

sha256:e3dd0f2d9483bd7829641b486407a753ca80c8e93f5d196dfb761a3bbbae24ac

Manifest digest:

sha256:b3f94608c22ffc6d21b98ebc3619de8c5f11259c9401bc23830addc618679c64

Size

74.40 MB

Last pushed

6 hours ago

Vulnerabilities

1
2
0
12
0

Support

Ends Sep 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:17-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:17-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:0a00c186b170c593062abbce7b77c4dfac14db7081a2436e69f2280f875d99eb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:20b9d81dd4af8320855e0b6220c2cd0616f61a06618879731e6fc3e3c6dcffa7
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:be81a7fb47de731e269e278e51fbdc3884f609354151ca6f82782ab4c3aa7476
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:4d53f8787dc1624ba94e638851015e087e23f8af107c3af22a2afa0c6b2117c7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:279397cc4a6d7a47b2070287596ecd2f52be2d15a1780b8da7bc32625cc8156f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:db81be7e80e668436a4325e8a028bf6a801e9e34a92da5bb1152423a91569f7b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:375fa21e524b6debabf72c308fa77183c8e941723a804c6ead3ba2839886b856
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:95aa199c1aa442be06f85feed5ffa52db536868f09c822abfa64abf77e92e32a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:94769f3b5c4a9805574f465b43f07f45ca5148c0837136dea1bdea48105bea2c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:15717c0fc65187149723ccc2f595b96d6974c278854908b2a9e0369737951aa7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:143823b1b4c03a8486aaa31dce620898c4652e90021342ab6fee461348569f75
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:039eaf626082ee755bfd785a1607df36427f167b9d730092527ed91d9b98e620
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:883bc8a6d2c5afc0f1482744df071688ca88ce17e5f05c4852b5f466e5bcb6b2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:32f82ed6989ac2c1d7675db9c9da0e46148f2c13b212954af204661033f847a3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:bdfaa7249f944897f9d5055f2865972b22d8a8adc46529f9deedf1812771bf2a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:7d1c7eb2ae8c771b0d8731b02a04f87144e9407a73c3974079df57992e7123c7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:3b3ae4712a29f3d12649382d4de0ba8778ee7c6c3859a3365517be19982c0486