Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 17.x JRE

CIS
linux/amd64
debian 13
Tags:

17, 17-debian, 17-debian13, 17.0, 17.0-debian, 17.0-debian13, 17.0.20, 17.0.20-debian, 17.0.20-debian13

Index digest:

sha256:36e753a16fe1fbef660cebf792a66fe2256c8d265eaa805b6c316b94971720ac

Manifest digest:

sha256:86e03158a0880bbd347f3516dc444d54c3c7801bf7f44542b4956bed22867586

Size

53.90 MB

Last pushed

14 hours ago

Vulnerabilities

0
1
0
11
0

Support

Ends Sep 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:17

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:17 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:2ac54bb59eee39aa7561f527e4ee88075c5fe84b416b79a89650595789d3a57c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:bf4a53216a48af63a6e83e182c351d29b6cd99e982a084c8f7cad890a213bfd6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:552ec68ee0063ab398c79c27e04f87af955cd019bda335f8ee8384780188cd08
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:a415109084f2919fd7fad30972057b976fd01dda65782fa38cbd58495162c2d5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:524b0e0e8a4c39f352cc4e921a0279ecbd28a336ceb85103a36a0b4b2a46837a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:e28ea14faca8c8659c6c57b0c94f9a6bf9fd9469d04fbdb796bf026b8028baec
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:1e1aa50e79391bb8700655658fdaeda4575810952faf6431d19b5e6efd9fe0a8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:68a53e569411122fd7d9dbdf1c88cff7358b8de1bca465ae1f56e3ec5c62cfd8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:5ea12b95def875f2bdfc9adfa5e024a9e712899e133d4e28173c55adc956bc2b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:44e85380c0fde3a643c507dceab63be4d0fdde3f0baf4227b33a2f86d6feaeea
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:c8586d77668cacd291a9ce7f0ff80a16af701b177658bc9d595a1c8657d72145
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:3ed17d92b1b34caf4d37b5736ce690a716236a10cc5d3022856257fdb4b0a13b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:a1ae3d66c6359ee18a7caadf5b10c81b7b470213763a576a9962c4188d49f059
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:759e8f3d3b9c43bf3a25ad1587a7003d68cfce339383fac18309f6fdc4e468b3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:7bb005a69008c6c47e8cb77cfd58e83d8c363066a2cecffacfdfc9b0bdeb4024