Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 21.x JRE (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

21-debian-fips, 21-debian13-fips, 21-fips, 21.0-debian-fips, 21.0-debian13-fips, 21.0-fips, 21.0.12-debian-fips, 21.0.12-debian13-fips, 21.0.12-fips

Index digest:

sha256:d0d4f5b26eeb8cbe11e74cb74ee89f2b707863502e680511b2beafc1ce99230b

Manifest digest:

sha256:cb5de64163e52338604b552e69d66f98d4dc2af0040b2c7c281f57ae72bb6280

Size

78.30 MB

Last pushed

3 hours ago

Vulnerabilities

1
2
0
12
0

Support

Active until Sep 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:21-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:21-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:e31c6e1c9e2cccbaf1233a6f2a21909e1fd0652627d2c3349e49f79942175d00
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:602c82a7143440c2c242b64ea6292bdfdf0e8d09b5add6be847150bc0aa7a8ef
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:d8e4eaa649eb8565eb1e2a90e9f048e055b257e185e67f294d031389df86559d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:d57f0236d59287421586f1211afeccd1bae56e42c7cb630b05a55314886e5e3d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:ccc9249c2171410f08a13cc4c22ba349a268601384cca08bc1c6cbb8f77f6787
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:8830696971f726fce2abcf72fd781fddc535eaeafa36d096a587119c4aefd33f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:f6dfd7d42e706ff841deb61ba676a7751cbdb168826f2aca44569bc174d662ea
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:ceabdfe71ef9c30cd8579c45891fd51be023e6f51099961dfe878d56dcab3c9e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:5e4c2453f688613057f2c5fc70551a6e6b0ae158cc7e54620516bf17e450af61
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:cf82a5d5ab966a1e20949684ef401f6e93f8380f2c981f658be308764de8a019
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:43adf143715063b3408eda45d64eb67153eb8c19ff6b1aef8178de3916877ab7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:b639d60ad7781038a50fdcd984653965df6f5620711a2116c37b2052e52d3c92
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:f99a42aeb23d72dc3fdc1a71149dadb72d60e92ad1f711732cc0b17aaa5a03f5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:2bd0abd4db0aa94c86758b556e39947ce0becc7b7de863f8d0f4740d76b4d339
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:3d965df2439acc8c19a16a8e534f417df41c96d877c877bc9208530a93059c0f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:6abbc051b48bf99a873820a945dafd10e2a948ee214659943358e3ab819f0c5c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:8dcda3098ce77f2347b6e55448be8a0de5007e4f2b4e3cde816c4e43dd75c7e4