Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 25.x JRE (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

25-debian-fips, 25-debian13-fips, 25-fips, 25.0-debian-fips, 25.0-debian13-fips, 25.0-fips, 25.0.4-debian-fips, 25.0.4-debian13-fips, 25.0.4-fips

Index digest:

sha256:08e1d26ea406dccc6da7bc3db279330e8045b1bdd1cf660ff92e1fa54f568e16

Manifest digest:

sha256:f428afd1cbee1441149909cc2de145f8aef9b599465ddc08bd9ebf1e094faa91

Size

69.03 MB

Last pushed

5 days ago

Vulnerabilities

0
1
0
4
0

Support

Active until Sep 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:25-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:25-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:9f5cd6aba25b1a2724a167eea64791a2c1f5216317d7ef238c37deff6b472428
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:c8dad6487f708457595084db30e7e4dc4144fffb9d2c9a4d11fb3036f7eb4c45
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:26d3cc2df5c97e1eeda7dcb5a026abba157587eb6c6669ea397280adbf83e929
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:9288a5f19c0a2408db85f84025074881eb2e8c29394079cde0990da9e0d700bd
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:916a0943c2e2b072947bf467cede0945919c699ef6cec5d4feb82b461a757e76
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:0477167b4419eef9ffc3869da5a71742242f8c839a7bcb50d2495636736740b2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:ed9423c296790557b7942da9da2eaaf2808ac0b33a5f21c4d276588f71e22e12
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:b81d6530ab49a39d3f7abbb9ec084d60e94af0cb3ccf61aade5027c4bd5f2bbe
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:e84d23f4739d54f07bbc90aa578ef0126c12d59fb5df354b9d381826c387487c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:b58b0419db5a2961f91b210449b0951b0c12cc51effb5a06f2ecc7462f589263
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:c236a72eff39a53b8bd4e6e3df9b67067dc98642b00bd636ac2fe53a9858a83b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:b8782b18aa417064cdcf1317257ac3d11c93cc0afe9313991ab31cfa946b4847
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:a2bc8e6d652ebd474a134cf60afe2a9ff2158151e37aaad836fa33dd626a97f0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:ff12afe38e80cf1ff503565550c91e2b68bd5b0d3809075c0384183a4fc098aa
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:a101753ed8dda103606793acb64a3c4600b74950f04eef9d7b05a4b0dddbad97
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:57ea4ce869f026cc7592fed6b0cfd6ab02c05ab220d05df41a51606e16e414cc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:1414062e0aeaea16d56ce0b9153e339e0eea2480cd2dba77789e11b48f228c1c