Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 25.x JRE (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

25-debian-fips, 25-debian13-fips, 25-fips, 25.0-debian-fips, 25.0-debian13-fips, 25.0-fips, 25.0.4-debian-fips, 25.0.4-debian13-fips, 25.0.4-fips

Index digest:

sha256:487b5cba2cf4e48202fffde4e181c31621665ecd93ea498df62f14eedc336a31

Manifest digest:

sha256:52f21b676afdbbacead015d8f85b56f94d47048b9faaa053f6b8a6e32b5fae37

Size

75.92 MB

Last pushed

8 hours ago

Vulnerabilities

1
2
0
12
0

Support

Active until Sep 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:25-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:25-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:342a5c4da07fcfc77f247289d87cde297d10ff2529eb9a00f1e013322c5c9765
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:03dcf60d677f232d24fd02842311d33a6a55c0b930f9dcb23c5cd1bcb7018cdb
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:085f5125d07d3110a1c629fb04b281b7e8e2dd2d29db1fae8d922d274231791e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:ecbf686acaeafd609a3dffc2345d11b5a311dd128e97f50595b2656017e60b43
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:95a85fda31887cb283358cab3fda7f131e1b9ed4f81474d8b695f6cfb43f15a3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:63344db4ee9edd58ad5edb984ff0618220ece6c2fdabf983ad0ce3de6536638d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:6a08accd467e5a576bc27a97a40770b55b8381a2bd88c87989af1008f0533d89
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:9448e7a2f1442d671ae0b431bc8280130114456a96795e2e675abfb4bf55c809
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:32af26dc14506605f36817e7d630886d92f0da44cdc0b48361372a3e5ac2361c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:d2b3fcee200fcb05fe6b3b75c2305df468353111db320a29dfec6701a942a82d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:194f0ffe23381754dfa9b9ae48f40f12fb539bfc0749c34254fc52fc2617cfb7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:e5fee20a688816d91f6cb7ea9080d8b4ee7dc2bb2b08fc3f2f7c2dbcb5a49bed
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:72aa1db01c3a6e9061921527ac76f7762b9829fbafcbe714f9dba198835bc7ed
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:3a44d0ee5a9511bc49339eb0b3fdec09de88f5f0a0069ae0a20a2b96b67d82bb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:11c9bf47f9847e9d145056b081a82593a64990fd194ee429cfcc4ce0c4e70736
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:f7f58c1c1a4671afcb2e38a1f59a3b30370b0412a503df959a7023967a0d44b8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:cb83fbc4301f8869e2ae5323569e3777731e6f1465cf534f004d2c40b03b3c8b