Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 26.x JRE (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

26-debian-fips, 26-debian13-fips, 26-fips, 26.0-debian-fips, 26.0-debian13-fips, 26.0-fips, 26.0.2-debian-fips, 26.0.2-debian13-fips, 26.0.2-fips

Index digest:

sha256:45c88c0f3e16cb5eb7bcdcbe682dd86ed0d8fcf727f4440253cec0f401b8eb54

Manifest digest:

sha256:74f54b59c9af444298f49f469b527968b522baa4e51f39a3b95ac43eaa522c7b

Size

76.58 MB

Last pushed

7 hours ago

Vulnerabilities

1
2
0
12
0

Support

Ends Sep 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:26-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:26-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:c9a6e440cb0c2e6034a175e987f5596ad3779e1a9fbc246e7bdea650aefe8d0f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:e087e4e59be4799bcba681413076b53b46c7c9b901c56bebea5089b96fa78df8
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:7f68a4471253741e9c33131df29097ad00a3c78ab1bdc81103e44287f97e4aa8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:32210b354d8abd5e3b49d77ffc66ce45d635ff82bb7b9568db318bececb4788d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:0bbd94904f724492964bf558a171dd6bf4a49e1c0f1978fa6dbcf7ad210225f8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:578f3172edb64950ce37b9a1723bea60c4fa9fe8812c737fcd23375d99e0efd7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:a854da28df63e4f860b46762d8509d64a9c197a2e52e08494983102c066f6e45
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:8ec84bc4bab0d300ce8a0f916f7d4a6e2474787f958d34a5f21d6a2c17b7d516
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:a48c2e8c0ae0b6dc39311053dfa050a80a4af002e85722d10d80f7a7e32e4ae6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:0e7ccb0d0244f9b3a74df58fab215e225fdb64c6c823c21c679bf5ec3bc43505
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:fcc324ed3be89653d1f420109307540cff38df234abb610e1dbf679e9d1732ca
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:338fa91da82930716def300ec9af75f9ab7b3bf28c29f0a5b2fb8cab311e15f5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:1627993ef6fcdc7be0af62173eb98e0d9e9a9f7ade3753296e5a57c73d7bf638
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:e46708bc2677255c95e149cd9b4e6bbc787c4900ae7172f9649aad45b7197af7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:09307f9a3274b066a6da7c0e9429f11dec72457f4c314c880700d54b28a6479c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:e05fc30a87a08cd49f11eea7d4e1ad400fb6a99ace248d57192d3ea927f8be50
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:4d8afbbc10103db7f231ad2fcd39a6d62411aaea45bc77f6ee1108f7ebf59d61