Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 17.x JDK (dev)

CIS
linux/amd64
debian 13
Tags:

17-jdk-debian-dev, 17-jdk-debian13-dev, 17-jdk-dev, 17.0-jdk-debian-dev, 17.0-jdk-debian13-dev, 17.0-jdk-dev, 17.0.20-jdk-debian-dev, 17.0.20-jdk-debian13-dev, 17.0.20-jdk-dev

Index digest:

sha256:54362fa151951b081bd778ffeb7a52a968a1b65c7e9ef20fc138d9529cd945e5

Manifest digest:

sha256:f23ff310759bcf3a83408a40faee70fc7b0742aff693b2e88aed88fd9f561888

Size

150.10 MB

Last pushed

3 days ago

Vulnerabilities

0
1
0
13
0

Support

Ends Sep 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:17-jdk-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:17-jdk-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:4d727ad9833cc5893a98ae1d32f77690452fdaf2684c46a41fcd8a26e5cdb81f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:f33beacfb0fe2fc955c5a00c1457e8094cfc1a32977aae26856565e441ce8df1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:37ed644fb617994df417ba1bdf9874618a37a7fcd65c91e349102fe80d76267f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:e793128e9e2a843e8a50744777b612fab7a60465d787e6263001236fc398338c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:4e8d8393c9d58168aa066d7e63f3757189ea6a0f72422271c969a0e6ad5fc4d6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:189676d8921b815fceb5653c7d8ec9616549749bfa10c7f19b0432e88fcb7be2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:1559227e5ff88ebf459362be844956c14654cb6873987232c7279498dd93c5f3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:a357044800157fc34669326977f68c485d7668afb3bfa5f588e4524e6d513195
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:9a9d7ac6bda60deff778575253ab37fe7e1c4fdf0762d4961a77eef8b904eeb3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:768d130c99beafc271f643fc37462109dce2b5435d3dda8315eada4cc9fba3f8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:ace0bec4dc6440ddfc0dbc163a7297f26bb189cdadfecafcc002ba61771e1e4e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:4b485b0ee2f8cdc399048975c420a52aa630beb4ac103ee1063aa3277c1658be
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:c297456ece28bb594d97b8f2e8f1778dd694f881bbf1b60a47118227d256ef32
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:7df82aea53f4ea74dbbbc0601a9d3f2c3995188b029de336e05c68b1163f1d41
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:4115ebaa46a550fc4965ec41079a94be4d0b3f894231e7b12181a7c904cabe01