Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 25.x JRE (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

25-debian-fips, 25-debian13-fips, 25-fips, 25.0-debian-fips, 25.0-debian13-fips, 25.0-fips, 25.0.4-debian-fips, 25.0.4-debian13-fips, 25.0.4-fips

Index digest:

sha256:b728c3e4a263bbe7a8d7fdeacffeb289e4fce517714c4f8ebcbb8c3baa6c5d7b

Manifest digest:

sha256:392e989544e67f0840265023ba1622aea862b58acb3dbb922135d7b6cfba3b0b

Size

75.92 MB

Last pushed

2 hours ago

Vulnerabilities

1
2
0
12
0

Support

Active until Sep 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:25-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:25-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:3498ebfae02eb5a1d43bf011c222b631e253b250477664890c8c19ea9ae29be4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:169622b26e238a87c35d5b0a951cfeaae072a4a421a6c9d61f9a972afb9b2b75
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:431961e079f9aea51724eb2576bf1e80bfc16ee3ca45e957d1e65c9dc8a160ed
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:7c00d364dab99203cc813f761263d33637cd3daea3e4f0ba22dcdd5d7baf2fdb
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:fd284adc8365a12d2387e5bbf0d062a6d9d6979dd272790662ace1c02afcd73f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:16e9d6c538aa2bc755a1b68bf9820c84d99581ae63579254b7a1ce92deb953fe
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:cb2aeca0eb16da33a84298c95e342b20fcd90506197da48a5c6f45c130bbcbad
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:180032687ec9664ff8128c1fda8d7bded488ca8f442039c8e2d14f18db834101
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:e630ed77d07b923595da30891e0c98a72360ba8ee4c34a17b4ce61b0985d1335
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:39f63912608ea61d776dd4252d87b5096c0307c3cb357c6f5059bf6dec47b7a7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:68921b9cbbd02e9f663cb584c86bb337cbc7d0fbf26057a44ed7c8b876a84a28
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:b2b8c801ac8fd75499a6c52470eddb5368ffb0768c913b11634c492aab4affd2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:2388b34846eaf7fa7eb7bf13eb87185533c147cea36185e96bf19519177fc192
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:8714285a6fb9bc2a1e5f37e17181ec405f2465545df5d707e010a0b511735cf0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:5f3b26ac4e1d20ba1d4647d8bc3299052ca92658a9f5e187aa567c0db7a5aadf
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:06ca5c1f7e4be233000589be50ac83cc37945ee3b9b55fd39cc98f65e18fc2f6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:dd5192c667583ff0f8a3ac0067698ed1019ad4bb82355cf617d1f6c1af86f0cc