Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 26.x JRE (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

26-debian-fips, 26-debian13-fips, 26-fips, 26.0-debian-fips, 26.0-debian13-fips, 26.0-fips, 26.0.2-debian-fips, 26.0.2-debian13-fips, 26.0.2-fips

Index digest:

sha256:b0769d47e2a7aeb8c6eab32b65128d53c0315c7a1de093032fa55bd147520073

Manifest digest:

sha256:df1c7db763f43b1d52f996fabd903bcfdde61fcd6694e1790fd4cfb8b508bb40

Size

76.58 MB

Last pushed

1 hour ago

Vulnerabilities

1
2
0
12
0

Support

Ends Sep 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:26-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:26-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:f3c04f9671eb208142a4c027da8ae20f5a0a885acb3dd4a698751373e8af7322
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:31b7a5bf7c4b4b8d4ee5807d63e3cd0097ae9644f445c5a9906d165a50ff5769
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:512fea825c2c621f20c1ad8bb223c06518d03d23d35ae3166e7724b79cd77c60
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:f6181f7e97683b175adf84b2bb72ca600b6544a8e0117b54f9fb72ea114a4851
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:705281b49586094521700c8da332443a0704c0be46dee2c0612141964b63bc79
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:02ca0d01729f194cc2861aad2017fac27e416f6bed9205c356396eb0068358a4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:bbedfac5e593252cbac1feb82b03426e3d3b71e0c4040def0793067a549ec7fe
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:b16527334f724ac5722be4ad884d84ffa94a718d19d9839cd1c2472db65828fe
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:d843a8a31df7a2be5f95c4b745047f6aa9db838c15d592b9c627303d5f2faa31
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:7f7bdcc9731d3f1b03fa02feb2a58d494bd86bb28efda7b46861b45208626d97
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:a817007386ecdd8eec7b5526ba0aa3914b2948044c92b4449129267c1c5df7af
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:f41b51290c4c9c5bfbed6ba1074a3f049188b984333363dc96aa644a6be8af20
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:8b00ed73964c84edaad12054afa2b43682a546317814c0abc8df6107886fa421
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:5e48c03bc4042c4f174a81ae85fef6a9d1b1301099b62b4e012ba546d55a3063
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:ac57b66ef6d2ba30965c26db8da0633f6b9b5b1485aeaba53beec324727dd6df
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:d3eb52e608dc15b50c2c974938945dcc3c541875593e87f2a37e8c1397c727d6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:29ba12b0b00e53f8dcd4eca8bfbee73c6222de391da704907cb3f12446927363