Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 17.x JDK (dev)

CIS
linux/amd64
debian 13
Tags:

17-jdk-debian-dev, 17-jdk-debian13-dev, 17-jdk-dev, 17.0-jdk-debian-dev, 17.0-jdk-debian13-dev, 17.0-jdk-dev, 17.0.20-jdk-debian-dev, 17.0.20-jdk-debian13-dev, 17.0.20-jdk-dev

Index digest:

sha256:54362fa151951b081bd778ffeb7a52a968a1b65c7e9ef20fc138d9529cd945e5

Manifest digest:

sha256:f23ff310759bcf3a83408a40faee70fc7b0742aff693b2e88aed88fd9f561888

Size

150.10 MB

Last pushed

5 days ago

Vulnerabilities

0
1
0
13
0

Support

Ends Sep 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:17-jdk-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:17-jdk-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:4d727ad9833cc5893a98ae1d32f77690452fdaf2684c46a41fcd8a26e5cdb81f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:09b46397946c5976454dcb889e8ba7b0f6ac1c9f1d147b385c899522009813fe
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:b273bed7f8d3f60867ba0bce3df97970581867f7109b9d60c6f223ae76a34d05
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:0b6f2561470fc058e9bc111de596a7c41f01751ff5943a699d54c08c25c097f6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:02bf7833988e1954da3fe9c1d16a5a8555c41d975193757299dcdf639e6c9322
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:189676d8921b815fceb5653c7d8ec9616549749bfa10c7f19b0432e88fcb7be2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:1559227e5ff88ebf459362be844956c14654cb6873987232c7279498dd93c5f3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:a357044800157fc34669326977f68c485d7668afb3bfa5f588e4524e6d513195
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:0a07a39e4025063862defc4bf45776ff7494fef8bc1ac909efda4f8898f28a65
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:a9c6e5f91b1dab4812a1f54fbc3dc22ddf101b31973f7e1b170e7f2375217e21
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:a26f6e4f8ec30559bf6bb855fe729afd4b7ac1204e6933ae478ab1ba3ee33be0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:4b485b0ee2f8cdc399048975c420a52aa630beb4ac103ee1063aa3277c1658be
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:c297456ece28bb594d97b8f2e8f1778dd694f881bbf1b60a47118227d256ef32
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:7df82aea53f4ea74dbbbc0601a9d3f2c3995188b029de336e05c68b1163f1d41
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:4115ebaa46a550fc4965ec41079a94be4d0b3f894231e7b12181a7c904cabe01