Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 25.x JRE

CIS
linux/amd64
debian 13
Tags:

25, 25-debian, 25-debian13, 25.0, 25.0-debian, 25.0-debian13, 25.0.4, 25.0.4-debian, 25.0.4-debian13

Index digest:

sha256:3482c46ddcbc3629e0b4416532b04a5f15f218af597dddc65522a56effa2c366

Manifest digest:

sha256:42c780be8057cc2b14f2fd5bef98d7d05d703952e98e603cad03c30fbd52c8e9

Size

55.46 MB

Last pushed

18 hours ago

Vulnerabilities

0
1
0
11
0

Support

Active until Sep 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:25

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:25 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:92deac5968f7f7c2e6775db732b6ba80978b39c968052d62c27ec173b05a0915
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:e112519fc4e229a200db70fe161fd4a7ee83440914869bdba71feba3b3785456
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:7d58983fafeb46bc3efdaa3c3d861de2d7c847bc40e8e860175b0e6a560cda15
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:1366f4bc8145e8af5f9fa1670d8e00f5be79787a578e57e9b5993005ea86cd1f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:222f8e6926b5e87461541c97e730b75e1f89de1af03068946338cc180be8e719
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:9e894e6a5f8b7dbed5f6b208ab2a12b184e12d775f9a30d0ee5b6369df980499
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:01f345394bfd70b9bc4b4785d27c35dcc3fee0420b1dce588137bdeb1bc7a526
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:c4922fc9ce4671983ab6df0a4747d0e9cb8833e9db6d7eba738f3b6f57163d8d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:2bc79f0f34e34de42989e67cab52546c66a6f173134bd33e62309ad3277337a3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:58fa0804e1d0a9d23eb5244be306045fe3513fcc35056aeb6f61a4b98e3102bb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:12d2df0a1ad75f6baae8a9d50ba344676170c7527a2924fb0edad92e0fef8ae9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:baf23e00d6017d35f06d9234ca516128e50c738139e3f391f5423c7744b2ed67
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:26a20a391159a625addc35f50f0a4496ffd63b6690ae4d19f87da820cc8f33d9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:8ce4d167a46fb3db1912583890ea3692cd9547720d8248d4279e6c82dae9d722
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:6c3490aad7b2eea6c4f682d3502f72279f1059b56ee320316bb7a1320d1c688a