Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 21.x JRE

CIS
linux/amd64
debian 13
Tags:

21, 21-debian, 21-debian13, 21.0, 21.0-debian, 21.0-debian13, 21.0.12, 21.0.12-debian, 21.0.12-debian13

Index digest:

sha256:a609b0e753c8c7da690424b3cdb1e20860c2f843f0cbb81ee06d69fc07073ae3

Manifest digest:

sha256:5d9e965f47aee9b9232868dbac179e60d9ea546c78dce9e1cb43513d8c4a7f5e

Size

57.80 MB

Last pushed

17 days ago

Vulnerabilities

0
3
0
11
0

Support

Active until Sep 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:21

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:21 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:bdf3fc5bf9acdba230e7b9bd4332a305ba8aed70fea8ab8ef52c4d048a0d02f6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:80bc4eaeab5885843ffdad308be2ca5650a0abaff8532b2d3cb090fda934ded0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:bbe8412d06ba6ac51adfeab383ba7e8c8fff43f94b21c7a93c7eadf96b16d81f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:04f194e3b22147a7fb247542fa54638eaaaee47cb7ec5ae8dc1e18e51392c802
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:820cec984a19fa66bca1fe35e5a56fb69e96b0d7e6c0b06d966dbee5948eced9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:a3ee4d0950ea2ed96217080cd5d8536f94e70374740bb1de8d5e70581d7d700e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:0aab9b3fff2c0e127a4042493215d01d23ce09670809e1fe5a663a71bcc5d496
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:d965ceec04f204eef2801571aa925867c681c6d24fd39dfc34a9ece69f66719f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:554ffde23ebf341d6fcb54305d3f5f64421a442c260c06cce6dc0a2cd0ed4ca8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:a69d9122088fdd3c54be4cbf173a1a9d0133a105667af9e4cdc65c535032463f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:b312a397d8d8bca256cb4652329ca9672d2165f2de17890939ce012e8c721ec3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:505283b0db38e118d607afa341e2c3f83c896e892dd7d6353f081fef5ec78aa1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:4d4dcf7d1df12ef7361b17a4e68756d549f9bba6633733fdb33c5749f452732c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:3d0e4c9d124b7e839a1afa3e826b345f5e77238ca391658e6ef4b6cd84f8dfc9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:d1008b8dffe6c30ca113a3cec432e60bae75b95085cc23aeff39d73cc756005c