Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 21.x JRE (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

21-debian-fips, 21-debian13-fips, 21-fips, 21.0-debian-fips, 21.0-debian13-fips, 21.0-fips, 21.0.12-debian-fips, 21.0.12-debian13-fips, 21.0.12-fips

Index digest:

sha256:7a237d24768ff66f47af08aa4c4b9d0630be06478690457481317096852e6728

Manifest digest:

sha256:b678f6df5d47da18b65516f1289a299c5f4968a77babacf56b1b7eec68c28a83

Size

78.30 MB

Last pushed

9 hours ago

Vulnerabilities

1
2
0
12
0

Support

Active until Sep 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:21-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:21-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:5367eb51990c65462b7b64de20cef2e0ee8cd509bb417dfd402d9ead19bd20ef
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:93300659ac5a9d5ffb4e557999df8c40d8ca78cfd138e512ca382077d0454d9f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:3259a0e3016df32c20f6a4cc3fea57530fcba36f2f08c8d7204f610484c1ef9a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:5762550b3b885c4321fb9a0aa2dda715c827b08def8b117beeb7acaee33244ed
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:742635932137e99e64dd998e94e24fae55b2b978a055b42ae9e5543f43b61f49
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:37cdab9ab98cf66f1b50b4ebf229743c635ebe2f60bff8c9aca035ec40bf36a2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:c63762b5685e5865dcef35ae2e9b239ef66ec15e113e8b8624e561fc22044f64
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:ea26f08cd176aa34a4c19da59a65e15a9bce0894a180db666d11fa5e073e3976
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:0609386b020ead7cc6bb7324d5e9cab018b3dfc028679e1ad7d958b0f9c2944b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:1a581d6552ca0176a31d1fdf35f4e06f4a379d52a7b30ee74864f8bd90f4b84d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:411c069f8cd06a05331e0a7657e194c4123bbf9dd5bef56ed65b10f030612125
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:dccac13dfb2b658b19c5924de9c27e5b2d092b60a6873777f2f64af2c84745f8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:ecf1b1413e33faecaa7a139342c40f8365ff7323eaa4b130a5dbc5e86b482518
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:05b6d004582f66bbc658ddddcf08fa1d63494c38d79a29024b331fb4d85f7da0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:2d060391bc4100296cdf0c5c936c212fc7edbdbc7e17c23cf53730b1664d4a94
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:d6c3e57016e94fae5922ccfc13fd05e33ab18a005b45c56454d4d9e19720f9a4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:61fce207c13d6de87396ff46c2c92d25f718f25e024d3c4c638f0a7b8ad6472e