Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 25.x JRE

CIS
linux/amd64
debian 13
Tags:

25, 25-debian, 25-debian13, 25.0, 25.0-debian, 25.0-debian13, 25.0.4, 25.0.4-debian, 25.0.4-debian13

Index digest:

sha256:9ce3ff6c12e6b29b355894e6325035c2a1b894076b5cd922673b4a1654f927c1

Manifest digest:

sha256:8fbfeea7bf692a75c989fd4b38735af057df086eca86685ac36c8cce05c71a30

Size

55.45 MB

Last pushed

4 days ago

Vulnerabilities

0
1
0
11
0

Support

Active until Sep 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:25

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:25 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:bad3ccbdf013827ca988df3275580ce38beaefac845ee0ff4c4fe78245604a22
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:54a6c0692bbdfa332e4a41c6fd9725a6df71e5c131b29d6aa195af8083ad6186
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:174ff699a5b1c782e4a21bfb3da6b5d66baf13435b0a5efee49b6059bf0ba336
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:9a874a0fd7ebd961b111840466c264752120b0591948c0b0080981418687d322
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:50797131cfb4f0d8c81bb05522b44c16869f43f4338809df84e23e2b9353be2d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:48084ef1f33a62170e60fbf004a9944b74e18f3dc65be0920fc6597024910680
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:7bf366ff73192b22a5453d146e379d9657647105b35d5f743e1d97bd39c3043d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:6ba19f86fe0df5a478ffb69d3928e5a68033f5e6fb2fa628d72c077de68d9dfc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:69dbb205c204985d2caeb0430252bde33c546200cb69db2accb362aaa6486a0d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:6616f6f87141ad4e72f51c4423e4e73557878311a3b1acbb7d0dc10943f957e6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:bd53a7b4227421077c3223ff5bd834e36bd05ecd26db6c0260d3dfefb427eba2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:bef115178c57d45455902e27ed71a911cb5147387c5ff07e3c4a6350d6fc8a99
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:a28f31acdfd0065d8e1ea6fc2ca57ef9ccd3b2ffd5d56a375e08cf2def8e9eb0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:c6489e8b9c694e468b58dad97e2abe83a3725ce91e7d732481bd42841d030a77
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:35a52aa5a4b37e57f793e3708bfbb41671548c33da7785b3df321505cf5ce9f5