Sign inSign up
Kafka

dhi.io/kafka

Apache Kafka 4.1.x (dev)

CIS
linux/amd64
debian 13
Tags:

4.1-debian-dev, 4.1-debian13-dev, 4.1-dev, 4.1.2-debian-dev, 4.1.2-debian13-dev, 4.1.2-dev

Index digest:

sha256:0c992a040de4568cdcd057884617cd3290f0714684d95dd2a56d8046be04f054

Manifest digest:

sha256:70a28dfd2fdd41cb68db08300198c52f8ffb21d78e28eeab83df9c52068a5a7f

Size

195.79 MB

Last pushed

22 hours ago

Vulnerabilities

0
1
3
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kafka:4.1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kafka:4.1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kafka@sha256:55e55ab79c5281b073a928054b1e649378d5f932f389d42710b612544cce192d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kafka@sha256:0fb580ca94c924a2ac613e5f87fa8d9fcaa32a96393821408fbd8e6ccef8735d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kafka@sha256:02fcfc4d5bd5737815c29c8366a194878769d18f4c6c53dbe05c43dfd141f132
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kafka@sha256:34fcd42cf149641f1d7d9dbbc6ea5dcc66add288d990a1d7e1a0521492656f32
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kafka@sha256:dc545b9edacd77e3efee87185e9b9be4d64f5670b67da809c4dbb3e0ffb6724f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kafka@sha256:64198de04a33e9f919d1ed2f903542efa44d64a3d4737585072af675535e4d95
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kafka@sha256:7e2b7c23ff7351965fc3832b7367cfe52b972e68e9a9247f331b6f67c11c32ed
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kafka@sha256:15a722b9da0ea995da02dd3b45edc06524c248058b8f062a31c0bd0fa45fa6fb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kafka@sha256:4b77cfee2db5d6d7f716d76c35d4db821084a96c97bf7c09c5e814a1151a985f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kafka@sha256:eea48fbbdfb8c3908167fc08e11032a087f284483df3d11e3c67deea1f9b5220
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kafka@sha256:1a358bcdc7b328923004988dd44240dd431b23e471439cfd0e71db44b37a0aea
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kafka@sha256:98aad7a05f4467f3d7f45a9d8d65b2cca24c2e11b256650a3751da44b612f1d2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kafka@sha256:0e0c40672ad36b0a35be2d7d608c7f09da5370160150943bccd54c4e407eda3e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kafka@sha256:4a4dc3b0a8501552159fcea83647474f64f336aa7c2db9950cd2257c437bd6fd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kafka@sha256:43a53b46057ea76f3969d6c21d3c55704e580e2570bde55d18d5d934caa1e3d0