Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 21.x JDK (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

21-jdk-debian-fips-dev, 21-jdk-debian13-fips-dev, 21-jdk-fips-dev, 21.0-jdk-debian-fips-dev, 21.0-jdk-debian13-fips-dev, 21.0-jdk-fips-dev, 21.0.12-jdk-debian-fips-dev, 21.0.12-jdk-debian13-fips-dev, 21.0.12-jdk-fips-dev

Index digest:

sha256:86ae0d9f8ac007c895a0cf83da707705c0707c23b5525efe14f4c818f58566de

Manifest digest:

sha256:cff479abc5505caacc4197d66c382318c7670f834c4e930d7ad3b1cae6bbbe37

Size

176.22 MB

Last pushed

12 hours ago

Vulnerabilities

1
2
0
14
0

Support

Active until Sep 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:21-jdk-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:21-jdk-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:cc7613918ce447f090183e3bbaf9cbed2f6c997cda4850c995155e7ae0305f3e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:83322a21cf9d795d27c1d58e33a90b581544e410ff0f805a8100f10aba5d3466
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:c13d2c89188732e7ba8a6500af123b0808bdcbe03c6aa9354bccddb1a81ce0e2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:751b1d1f6ce3a1a8f65b2e6241887776a177ebeca11c6cda9d5de15ce09bb590
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:0059c209e8446523f6596d50ed351793574d7c9b967f8899ab61a249dfb866ff
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:4c0cd192391f0b61c14cb32f16744d18c0754aff6b6668a3152bce149283a582
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:69c56370e013195ea6d495e28c67001e71cb40b71937071e2143e3ba95420cd6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:a13ac2a9f17966e1cca75be0d76f4c2a6a8cc449a679130ee9a7ff1fcf153bc8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:fd830e0a492ea2f1be00d665de8ba8426e5fad4d698e538ad761e8bfcbbacab5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:2fc07280467ce4747fb66b9af1afc5180a0dc403cb367eaeb1c320d80c449da8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:d912b0b8ed9929c635d1151450d0488ff6e363e6dfdd152931484826a8ac4b24
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:98ad6da9f8ee6a9e8c514588aaad3b2477dc26b44f784f09059d70e6bafbaad5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:0da32ceffea59ef2240e5f5c656031c73d3bd3580381c2ad34f99ce5d893bd7d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:5432d04dba875a8a5ba7b7a405d30c1e8db33703e40f9cf3fe4888f3f3ddc895
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:1e6d2da3e0f15d6c4edabe8e3b17e93506b8156b422834e1d7eb3bd462455fc7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:da4bd125b19d72640a9db61c4e79d56f01618219699566193d7aee2c75ff5ba7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:1f9b98fbb53c947757480bfc3bdf19d3ceac53cd5c55eeccdc283f83d451525c