Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 25.x JDK (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

25-jdk-debian-fips-dev, 25-jdk-debian13-fips-dev, 25-jdk-fips-dev, 25.0-jdk-debian-fips-dev, 25.0-jdk-debian13-fips-dev, 25.0-jdk-fips-dev, 25.0.4-jdk-debian-fips-dev, 25.0.4-jdk-debian13-fips-dev, 25.0.4-jdk-fips-dev

Index digest:

sha256:b29817d86452c2803b6072c30b6c1d069fee2c9452b217f5846291a5d60b93f4

Manifest digest:

sha256:fdabd86f8f0887d8bdee01b1567d4d013b133e516e47b3bc2ec2892840405906

Size

182.96 MB

Last pushed

6 hours ago

Vulnerabilities

1
2
0
14
0

Support

Active until Sep 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:25-jdk-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:25-jdk-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:e86351fa7d02cbac228349ee33e2be0fa7f2170340ce6a92f218d3cd21ec19f5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:dcca28f819bca1ca0e2c2182e411a1d32dbdbf54c30b43b0ebd8bc5b4535cdfe
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:244dd9907a54f1e4f8bced0a620d33b0b384e1b702787676fbdbf24a3ae1058e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:8e32176968f483916ef8d2cbb76a2fe4ca3509662fb80b1dfd123696e40563d5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:6880e5d744429d5bf1df30aa953efd1af5cb2b8aeb399ca4f07144e163c655a3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:6659fb4eb5151619d09d631e41e897990c50a899e0571358a8fb1b00c297533e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:182b9feb9700ddf37d341ddf3256405f3201420e27de81e417ff6f304c09ed65
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:319e0f2db1e9748cb4223a92be6a781ca2b3e9e455410ba4a228396e418ba41a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:8cf0e454905c848f1b0ffc016c3fc29638a00eb279e56911040271cbd3415450
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:d4193ad560b36b03f433cb71d03c59e4c9e96f4873fca06eb0ca64368c159ef7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:749958c83146f4c20d7bfb403ec6f1803f7525d668f563f8be3ab356ea19305a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:3708df4bde8a2e5a8f25c42f03d539559da8fc415907178c9caa8c622c844c70
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:5514f65689a87c7758361cfebd46e11010ba5d6d153983b4598e273a12a33e43
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:419afceac1941dd9856e6fd2067b6bf450cb8618dc31e37f9638ec230ae413a7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:1ebb6c971442c0266523c94cd0fbd3f30e6f5bf9f8aa0aac1cc4c18521a7fd28
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:9a3ef6413b3b7f130b709bdde0812a8eec422df2fc92b747411f8d1e3e5b551d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:d8710dc9f5a40df73cb314d4c7d165b48ce4d219e4826378c04d299189d976a3