Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 21.x JDK (dev)

CIS
linux/amd64
debian 13
Tags:

21-jdk-debian-dev, 21-jdk-debian13-dev, 21-jdk-dev, 21.0-jdk-debian-dev, 21.0-jdk-debian13-dev, 21.0-jdk-dev, 21.0.12-jdk-debian-dev, 21.0.12-jdk-debian13-dev, 21.0.12-jdk-dev

Index digest:

sha256:d362c6d670e7ae111d863683808735c50b58fc9918b1ae82ff644e74126b268e

Manifest digest:

sha256:5510a3fd623d9e30543ecd7dfd010dc39b42c1f2b88b0b04c2e612e14d2d15aa

Size

159.73 MB

Last pushed

5 days ago

Vulnerabilities

0
2
1
14
0

Support

Active until Sep 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:21-jdk-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:21-jdk-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:9aeafbcdfdb7a1573114edc93fb66e16c09e4080ea4b1a5d48c76ca129824a2b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:b78346ba1768259ae671e41c3b126cbdd0f947e23383c3bec4ae1aa13ccae274
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:09f72b44cf94bc8f3bbe43122c791472b202a8caabd510e81712f1aafa7d7c32
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:b0c96fc6c3a66c53d037c8f10f31ab8c5cad398c4d065f3657d6845b7e46d71a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:f3a99274dc37e7f051cf590b10580eabfd0b63ae1e5b74cf734a1a8b9f8f9c15
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:dca8214192e818bd59672fc2fb8f129a4b1d52022d0a78febf972512867b9bfa
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:2ef0a9392b23befd806279e0d5f0e39bad7206cca538c3366c9387a71342625a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:9c202265243b58de2873b8a216b34a4e52bcbf12d93a36c77ce07ace6c27e9ac
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:0701b97171ccd78db70a2fb132cc0bd2cd82aec7d4d64be48faf63395c6b2905
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:c450c05518a93f63fe877519e66aef58a5956ef7373a72fb3458cfa7c87b6bbb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:2b6f564311780e9286851be2173e925dd2b6353a23bf6693e793540c1fc0b9b0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:7242de97975246c0aa865b72d30b191d8fd02d70eb6a6096908b912402defba8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:3565412eb70757de2c4594c5fa8e07814a9eb6cd6c3dc3efb0b4139372eadaf3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:42fc51b3fd5ae2ece7a85e9217b3f9bf8ecb73789bf2e894f906d7102892b7e5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:1d847d255204b704a846579cc349a46e03bd787ad4a6ec6e6e635e635d068c99