Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 21.x JRE (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

21-debian-fips, 21-debian13-fips, 21-fips, 21.0-debian-fips, 21.0-debian13-fips, 21.0-fips, 21.0.12-debian-fips, 21.0.12-debian13-fips, 21.0.12-fips

Index digest:

sha256:b064ee0573531cbc33b96051cf071019092dfb792de595111eb1e03c3f90eac0

Manifest digest:

sha256:085dc8f758738090e16cc25ce79efd305456037ee38e86f7c6a54b3bfd20e413

Size

71.38 MB

Last pushed

2 days ago

Vulnerabilities

0
3
0
11
0

Support

Active until Sep 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:21-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:21-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:610409b2c192e3d90583f4a16abd65ed0370b694e79c9cd434cd520642cef8a1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:67fc47fb403aeb0d6a2186a7f9c4f5cf772c4833e807213cce28a31c369851b8
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:cd941a9b330a66a3037b2e61e551443347625c2c59eada73308b53711f2c203e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:8ae85adfab3d695d211eed1ff98f1cf2cd973347c061511702b33616bf501662
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:2f9ccdf381b2748079ffc2557fef350707b597ea8e35754460f2dcffea66de80
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:bfa502a63dfc7905102e2213026c6e0c55ac48c363d807b3c86496bbbf6f77b7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:a2127b75fd70c9d0f8eb74b6ba971c6ab9ad5950b8c7c8410584c762224b6e8b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:73e30d325a61565801cad4b9232c1021acb6b593e2f8b31e10981dab430b3c67
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:946b18e09eab6d108e55f54e3b7a801ca8eea681f61c10a0965ceb00bd53129c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:7a0eeacdf8a2bd93ca1f3624b9198fc2dbc6a67fc78aad6902710a8f184548cf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:894469e8078c5d5e3541c232331f1b67ac90706c91eb777aed27a8727744f810
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:a3842419679c6926f35a3746332c456ca04c2838b4bc857fa04c24281f22364b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:016b971bc9506456f3a9bd42cb7b918f1670b31b0280e13ccbae1f9450c8fc38
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:674e406b7f82725e25c3b506028cb125ffdbc1dfd847710eb8f6856614094d0c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:bb1a29927507ab98375dc985d6d2091f2e338c3fd5a7627209a4499795cd0467
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:0bcef17de0a555d4f7bb325cbebc431a9a3a7932944f4678f71260c2709d9827
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:4b4cb40024954a36faf66cbace983abb36053d16a821dd549f16ed9e1aec7b14