Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 25.x JRE

CIS
linux/amd64
debian 13
Tags:

25, 25-debian, 25-debian13, 25.0, 25.0-debian, 25.0-debian13, 25.0.4, 25.0.4-debian, 25.0.4-debian13

Index digest:

sha256:3482c46ddcbc3629e0b4416532b04a5f15f218af597dddc65522a56effa2c366

Manifest digest:

sha256:42c780be8057cc2b14f2fd5bef98d7d05d703952e98e603cad03c30fbd52c8e9

Size

55.46 MB

Last pushed

5 days ago

Vulnerabilities

0
2
0
11
0

Support

Active until Sep 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:25

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:25 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:92deac5968f7f7c2e6775db732b6ba80978b39c968052d62c27ec173b05a0915
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:cf6fb2f8d5088ce35f3198a944725a5c20e1d40646af5cfc230c61dbfde6a0a0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:31469524e6fb645c92d648673ce4e9199c99f0f9d51b73c598d9edcdfe009b54
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:1bf8e5748abb52a55ceb4ada34e54c0fff6f1dc7f75f5c17f36e5facd768fc58
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:4c46a58939e1a3608756b4cfdd391b8c08463ebadd4c901bfcac06239bf0d6ac
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:9e894e6a5f8b7dbed5f6b208ab2a12b184e12d775f9a30d0ee5b6369df980499
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:01f345394bfd70b9bc4b4785d27c35dcc3fee0420b1dce588137bdeb1bc7a526
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:c4922fc9ce4671983ab6df0a4747d0e9cb8833e9db6d7eba738f3b6f57163d8d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:67011790235606b72544f2d22cb756704d48b13f759904444d2a35c9007a78ed
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:9b3db020057360826708147ca5909f84b0857936b7214bfca16b0ec3e3f52442
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:1bba99cf90717083b75c31e66635e7bf3a57907f5068c091a31d56b485f7e781
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:baf23e00d6017d35f06d9234ca516128e50c738139e3f391f5423c7744b2ed67
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:26a20a391159a625addc35f50f0a4496ffd63b6690ae4d19f87da820cc8f33d9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:8ce4d167a46fb3db1912583890ea3692cd9547720d8248d4279e6c82dae9d722
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:6c3490aad7b2eea6c4f682d3502f72279f1059b56ee320316bb7a1320d1c688a