Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 26.x JRE (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

26-debian-fips, 26-debian13-fips, 26-fips, 26.0-debian-fips, 26.0-debian13-fips, 26.0-fips, 26.0.2-debian-fips, 26.0.2-debian13-fips, 26.0.2-fips

Index digest:

sha256:574f8afcbb1a12b3ac680472683d05bbd3c48c9df27f4dda4cbc6cabb58a6447

Manifest digest:

sha256:aa6e0cfed0111d3c2760234676f65b775ec2af0b0c7a004873a83fd7de3d6415

Size

76.58 MB

Last pushed

6 hours ago

Vulnerabilities

1
2
0
12
0

Support

Ends Sep 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:26-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:26-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:e70ab8ac816a2caf320b76556c8e71c772b4cd428fe61d8c360575bfab444634
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:f1bdf449ee0d0cd9a81854e271894e087322af9e0037a44cd819cb0475143d7b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:9395c47605d679c4eaa3e09d1cc1546f786749a35727c0699f6b8d8d32ce152f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:14ca23a131fd51aff5fd92fbe6e405eaa663670fecd37690d224692a780bfb50
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:a584d4be670f8f391dc48b04f6493d152cddd47a019b2e650e1c855b795805b6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:a3ce41ac669645ceca804b3d8612f6bb865f5c3a3e4312e9cfde06d0309e9c7a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:5e7c42b3e3b2fe7e52dbe17445d15991c7094097f27ea390ed6cbfd2c2fd8460
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:10b48b9e2660563a9b4975822c56ad35f25de4ccccc27d6bdd393acb15aac064
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:04863655bbc8dee75a4410d77a1a10e4de6fd6765c2b21a6302e35f5114b80c4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:8c72711380ef8b8c883a87a7d3c0dcd92396908436948a25fee842634d69660d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:2bab4bf381ca94193baa60859abb5f983a41a4dfd4d7b8c17a28fa0cf32230c4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:381186e601102131b1d04b6b7b222f7aa23d880abf0f8f2b33cd972527d180e5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:add8df28cb9a89adc7f36c5ea679d9adce3c0ca8e938472bed26a117aa64136d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:2079c5487179c5c46a7b99b612f09218cbb31b7a91067805c287382d1256701d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:e9efd1c0aa5b3a86ccbf0ff54385e6225e3bfb777338f51d8131efc90e2db674
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:3cde64a67dc0e1187824253b08398a687418a52b5a1821d322abe12f941f4c7b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:4aedc2520b94dd1a36c8df1307100c231e796bb18e42bb61e86ca8f8dd90de9e