Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 25.x JRE (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

25-debian-fips, 25-debian13-fips, 25-fips, 25.0-debian-fips, 25.0-debian13-fips, 25.0-fips, 25.0.4-debian-fips, 25.0.4-debian13-fips, 25.0.4-fips

Index digest:

sha256:f79f6346c53806717965c2e364f3cd38b40c9a5fd524f7c339bfcd4308679344

Manifest digest:

sha256:4a5b4d2843a57caace5980ea429a27994a0eca74395ea3d9cb394ef485cc8cbd

Size

75.93 MB

Last pushed

3 hours ago

Vulnerabilities

1
2
0
12
0

Support

Active until Sep 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:25-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:25-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:83ef3e271eac3d07aceaf41981dfe9e7125d33d1700fca19ccd2163e3f81d123
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:c868368647c92f2d347e0e9a4ade16fb8ca73d2234c03938087e3221418fa697
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:cea7735b21cc781b1f794d5c0b57488b80b9f84d05ed194753ff4bc1baa0b2e7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:9e61fdad0061a2f411205908247647428fc4e1bcb97f26a3a1efb3f70def65e7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:2e4e1e8920128d42c3d564e070926d9d375ffa767b5d0869462368c9452ddb93
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:6ff3dc4fe3390f289573812d2318dab64df134ffe1a1aa1e320b860aa5960a9e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:02adc8ac19f56944f406ce4d8755b93e9b759e2f76d5adb1802a7215f5d1fc82
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:44ec1605c5ccae28f21183843b57a536258299bd1a0ea565c70352f2eedfc083
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:f7b64c11bc714ae865b15041bdd8b5a0e4ffe3f56d2d7db803393b8f136d1cfe
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:e7ef4416614c40d3016919860ccf1a70cba911fcf06f2f9064bf49c29d651d35
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:931750fd5a65303b070cd566f1ecfb18c03a7aca51e06477d6759d4446a95491
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:0bcf7e7306cb03d0bfc5aaee5c36989845743d74aa35a09347853926afa66e68
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:543aa33bf37c7dedc31641218110256b13d033500c92f1a6223627d8e210897e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:308ee7d62da3bc8f87cc90771b2dca1af7d51c961b4cfddf2ab3c006ffd9ce1c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:66e53d6da23244bca26c6e903dce31e593288315903883da537412994838d0cf
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:995a5128ba5093a9a0132ea7bc34a2f0d6332ae2660e661df883487516ef433f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:ae84f9e9df68478d69654bd468ecd6519416e1505ebe99495e45d10fb53b5775