Sign inSign up
SapMachine

dhi.io/sapmachine

SapMachine 25.x JDK (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

25-jdk-debian-fips-dev, 25-jdk-debian13-fips-dev, 25-jdk-fips-dev, 25.0-jdk-debian-fips-dev, 25.0-jdk-debian13-fips-dev, 25.0-jdk-fips-dev, 25.0.4-jdk-debian-fips-dev, 25.0.4-jdk-debian13-fips-dev, 25.0.4-jdk-fips-dev

Index digest:

sha256:fa966d9bbcd5b37509fd362da16b33260a3eb92a16c929c86152f16e8b12c18b

Manifest digest:

sha256:7df996825b2e395de165160c5d99ae042fc661b0d52b93d0ba805f95f84226ee

Size

176.92 MB

Last pushed

4 hours ago

Vulnerabilities

0
2
0
13
0

Support

Active until Sep 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sapmachine:25-jdk-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sapmachine:25-jdk-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sapmachine@sha256:8e6ee20c3ee8998ae38b742114df836f73774e2570349c5f0b5771d397d3b2c2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sapmachine@sha256:bcb6cf197a4a6979e129903e42dbabbe7b23e18a96f9abf637eb53c9df6000b7
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/sapmachine@sha256:d283a640a281535da52814ade9e97ae604f15306ec261d1adacea9e4c55c607f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sapmachine@sha256:64c2db02eed836d08e36f701ed04dfb95c9981ea3621aabd11db2b4412738acf
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/sapmachine@sha256:0f03492a614202b564be3dc0550b703221dac6793d6322536699d588477ff6bf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sapmachine@sha256:eb26bebe0ae644b5a08d8395dfeee99e106ba37221552dacfe65a2ee99a5199a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sapmachine@sha256:aa460ec3e2bee50bb569b224577d3650a453f1a0b36a462ac03fc005d01bfb48
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sapmachine@sha256:fd639e54d31b83e16d71cd8685aabc4037165a604116621eae949d031149fe91
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sapmachine@sha256:bc745ea9110f5ecf06c6fd9e48ebb4636b561bf0943b69feeec6a82c6ee9f913
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sapmachine@sha256:a4d8dfc0ba850fb4809c8a15d6215d68a873a7539b61a6cd97bf24a20dc1bc15
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sapmachine@sha256:d82fea6d7b4e85a297b9f881049dd30022784b6451f73222630fe8893831c523
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sapmachine@sha256:e96c3a424852042fabf2c832dc55cf2363af86f721b34dc9f39e96b76efb2546
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sapmachine@sha256:518ac56cfdf1fd0cef11081f2223186a82742089af7f5d5500d421e46696d9f0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sapmachine@sha256:b213c425a5975af3f0d4fb72e74144214d953b44df6cc2db945895cc50014cfe
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sapmachine@sha256:7268053b001b3cc77429c3eb033f9af70c0c2b2dcc291d4d6b72d9a05cd94b7f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sapmachine@sha256:7626f7d7758cc8aac8fb1fb5846e8674e9d15625e3fe90bcc11bb49a6dcb0054
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sapmachine@sha256:7b92fd1b90eedaf104d9b36cc083a4f615e01a535052c9556cb8ee44f7909d88