dhi.io/sapmachine
26, 26-debian, 26-debian13, 26.0, 26.0-debian, 26.0-debian13, 26.0.2, 26.0.2-debian, 26.0.2-debian13
sha256:65bb314f86a1660dc183b6c8f20e8d71d42e2c69da9c2194eeedc21676d50668
Manifest digest:sha256:020fb203aff6ff37cf8d0066d4234b256e46d8e698d56f36cf1bc43aee38c15e
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/sapmachine:262. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/sapmachine:26 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/sapmachine@sha256:3aba0c3d0998d22d314e4f63389ffde95b1fc93c6fcc9c2f20269038f07afa3d |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/sapmachine@sha256:c7ee81f35f481ecda24e4c9cc1c58c8cc8f6ef11a1d7f397792ef039fceec939 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/sapmachine@sha256:fd376b6b5af5ca5bb97055da3ca8843c183928f698f2c2cad5b5ac471bf46804 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/sapmachine@sha256:0f4219e37f0138b2c6296ce801d0f5fc97a3ed050cb54aba4ce3ed27880b57a4 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/sapmachine@sha256:3f43ab04cb1824fe10e0aee9cec00436055f8830b59d746c09aaf4617964fa35 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/sapmachine@sha256:2b748959baa822757e47c9b808252c1c1fb3229696bcd5b6930b27d7a627c38d |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/sapmachine@sha256:f8d824a20cafb3c1cfe25e0fbae71d53eec76b29f38325298abc4c2ed258172e |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/sapmachine@sha256:d9ee213bc53657f4476185e638da654a140e146e2a95e2f5f71fb762225e1a08 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/sapmachine@sha256:e851535fe30adaf457f00692d72e745af542babb1e161eb33d6eee4ef206f2b3 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/sapmachine@sha256:7a5248c31ffce6011b7e34d4dd4e4ab51450437139804b2ac089cb4cae37aa63 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/sapmachine@sha256:264de27da46e6d2bf430fcf716f14a0b0039b51f72f649c28bafd51172ae8e4a |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/sapmachine@sha256:58798f471b19227b5d7bcc32e09aba96647ee6f6669b682f9e1634d7f475e53e |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/sapmachine@sha256:adbcfb9f3e3f63eefa1bb7446fb77af98de503a1b2645add4851828f7a45bdf4 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/sapmachine@sha256:250094b1dbae632e6eceadb4705836e111eddc5cf3dd8e06d6ccd39ffd6230bf |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/sapmachine@sha256:b9910f7ddfb34f154aeeb8a8e8d132032e4a04bb227390d0dd3d219a5f98b841 |