dhi.io/sapmachine
26-debian-fips, 26-debian13-fips, 26-fips, 26.0-debian-fips, 26.0-debian13-fips, 26.0-fips, 26.0.2-debian-fips, 26.0.2-debian13-fips, 26.0.2-fips
sha256:f65c76ee70173d4cb60ac693a44114c027caaec3aaa74d23cc3463c2f16b54e6
Manifest digest:sha256:5b638460851fe99c4e8a38ed69391fd53b2f4a0905615227f3ea512474f46f35
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/sapmachine:26-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/sapmachine:26-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/sapmachine@sha256:46c45503ad56fabf4377f103e71465835f21c177f008b39b380c5a58d9b04117 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/sapmachine@sha256:ef7b0b50b4e11eb82d2e9ccb1ae642e7b9a41a41552d84b0eaf0c86e81a9f918 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/sapmachine@sha256:1188e94e4ce4dff4e8ac983265ce6345c0e151cfb1af99f6c0a3a3055eb74749 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/sapmachine@sha256:43be1dfd7e49bc94c5477edba3a491dadfd48f9c816183ff9461cc5893a03170 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/sapmachine@sha256:a3d23f8cb600ce58ed07e1f12e6dfb2ef9b3c634eb062f3834b677659dd90520 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/sapmachine@sha256:402f4d631d945389fee1f54737f1dafd73994bb767b0256cd7bb0180d3dff9ee |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/sapmachine@sha256:a89b18c23a2d4123221ebb15ea3b59bf7a4dbec53195b9984f1d4828b0a556d8 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/sapmachine@sha256:74160e708dcf2100efff88994c17ed658bc4e71f800824909f6fdb067a6d98a2 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/sapmachine@sha256:24e1b5a416d7aa441db697d56f7d570955e4c09fd7e3e097a9ee6d0b6d4f002a |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/sapmachine@sha256:09a4b877115ef8751d9ac2c69f26a550ca6b226608c6931b467feb8186f4efad |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/sapmachine@sha256:59787e641b59d3a4dbad75b8e19041bef531c7203dd6b214ba138dcc380820a1 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/sapmachine@sha256:53a0f4e609479688b01e1e66f464f91b3bce91801f12359ed9ca9d7c8122d042 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/sapmachine@sha256:2b9ce110dc9636280e603228a1e962126a9f958b481fc49da11b07fa701468c3 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/sapmachine@sha256:c5d7304ad277a639387314b9129fc8ec4721434841120e747d052e70ee9325e1 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/sapmachine@sha256:de69e25ee3502bcb689845161ad7ffb589287d9dc5fbc7e63d45ac104af93208 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/sapmachine@sha256:230fb7fbae0830d387f0ffaa92d0e056754f111b7c16f74a344bb82e92d5d268 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/sapmachine@sha256:2494fa8e1384e1b599ec2b0d76eea6f931b062c961fa0d379c77dac99309fc1c |