Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 21.x JDK (dev)

CIS
linux/amd64
debian 13
Tags:

21-jdk-debian-dev, 21-jdk-debian13-dev, 21-jdk-dev, 21.0-jdk-debian-dev, 21.0-jdk-debian13-dev, 21.0-jdk-dev, 21.0.12-jdk-debian-dev, 21.0.12-jdk-debian13-dev, 21.0.12-jdk-dev

Index digest:

sha256:d7b39196a27086153b6819ee09ae6b505f5c3fbbd3b052434c5ff49c05cf0617

Manifest digest:

sha256:88ba04d97f935647bb034bf2b6a0892eef55f5373dbd1df3bdb6786ad683ff99

Size

159.72 MB

Last pushed

3 days ago

Vulnerabilities

0
1
0
13
0

Support

Active until Sep 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:21-jdk-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:21-jdk-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:eaf9878fd2560cdbff1f85609cef05f902d9a5c2de5bad0a222a1d7a6d1d8887
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:2316dbfd434d666c46c373772b2e0ee6de357d892afccf1e1cc09720217e737b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:7784af6175f798cb3136d46e767996b78508f4afb1ecb03d82752e8b7c627789
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:c2e11b44db0d137afa8b14bab016ab3b4147a7fc57d8bfd50cd30b13097870c2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:4531f235f31e4c5ff98c1f9dce121e447fdc130f60218e7b3876a243792d476a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:eba544877d02b8197a26113b29040e5ff1f6a208485e7a0859cd202306e4b42d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:4ae8c3a31c1b34eff4b5b2a06f008cf4fcb54aac7c0deadf4d99f0939c0bd846
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:4465e0aefb6702cddda36a0250eba7a5f5c08c2c0e6d2704228ddf39dfbc277f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:c430848a04b54cc04c8149582280fb7df8d112f5d835b52b47cf9afc3d231a0b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:d0b7298025661dd46b4a6a0a1fe5d4e170e64d7770d805ac0484e45e4ef120cf
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:2f0d9c658eb6ff99d3620943a5d6e4d6c2aca497e47ab0b6f21d09d10317a7c4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:4751d75fc4918e74a2c930055db61d7f55cb2f7129556787aeb2530a9ec0b8ee
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:311d80f562ed3117ca9461cd06458bc4efef7ab7982b14e05da85682b4ec98c8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:affa25cb253510ac7c8e16d88d148525a9f6b913f2835a615a07400196258b99
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:1b29d9238ab128be90a490041d313ac16c767c76fc8c9dfed73511c5b8815374