Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 25.x JRE

CIS
linux/amd64
debian 13
Tags:

25, 25-debian, 25-debian13, 25.0, 25.0-debian, 25.0-debian13, 25.0.4, 25.0.4-debian, 25.0.4-debian13

Index digest:

sha256:cac1cfe16497070e4996f9afacba944b1a04a1c2e556228343dc7a4853a941a8

Manifest digest:

sha256:7360b4e9457e9d60e16a150da871d6af284a8f6b9fcca127e34756df71dc6e86

Size

55.45 MB

Last pushed

12 days ago

Vulnerabilities

0
3
0
11
0

Support

Active until Sep 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:25

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:25 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:819694165f24db47e37e251bbfe95c74c9cbfe2cb2ef00ca857c0e517c409047
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:f8b44efdecebe0be3bf98e3b0c0c70589dd140f10971adc017e5d22488b87e95
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:73655897b0ad5639957b70e799957ab2390c3bac5e3e0b12b7971ef8c2704ffa
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:c732418dd3b34864c9d1ba958b3ce3ee350f4c50da33848619d84cafc19c1f13
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:a7314b9b06be07ee6488ddcbbf6be655f3e796bba4bff6f5f35d0401f31d8979
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:ed30d2316ca0fc835160af42003862444425244ccbbe287e58359ef4d4aef636
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:69bb2354a008f88bd4f5accee0065948c9d53288398476529f2d5b65d822be7d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:a938fd757800f657b56a42a02ec09b8fcf934c8ed58e3a1e5136216df3e2c91f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:536c5138dd8672c2e8721e00d85e76e31bbb626f6aa58dd54a527a7255cf7060
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:ceefff31633d5574881416cf3bf381d1b92f75e06e60a681cf75bf7c9e0d01d8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:2efea13f9903b3707bdf3c2e29ab4f0171df4ac94ea10dff2d9e9be96723dc29
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:1a0a5abf521e929c0eb97ddb29b5874f9015c97d7f88064c4a23e62f5ff79560
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:0ff2286bc985599f728ce3db6fb3c3460424ac23819adf3d5fd427fd21de3f26
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:340366f20cdf7189de26a937e83f4dde91dc56262348586a8173744d84980ba6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:ce5d03a83478864b0335f9fceb1d5750f73c9140cd976da58dfade16ad7415f3