Sign inSign up
Kafka

dhi.io/kafka

Apache Kafka 4.2.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4.2-debian-fips, 4.2-debian13-fips, 4.2-fips, 4.2.1-debian-fips, 4.2.1-debian13-fips, 4.2.1-fips

Index digest:

sha256:fa73062d0555895d971a092f5c7c8ffa73dfe15197360864f20fdb53e4febc1c

Manifest digest:

sha256:490c4dc576fb885e969bcaa2d545895543dfdd0c48f4bb3ed65521b0ffc791ed

Size

191.66 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kafka:4.2-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kafka:4.2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kafka@sha256:84c63548172fffe00ee77a616525ad41c09456affb93d00c2083de8e2105033a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kafka@sha256:1b56b2c8c35a973c062c37c2e736adfbe8a84183b3c6461082090f5b4ee40dc3
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kafka@sha256:0b14ef533fee11f635282fa9835cc8b77d2f06eed6af60ab5855aa17ff8a39a6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kafka@sha256:e934e6bcf0a399987c56315ff20f5515aec459120d392a6aa6a5f7340a26eb15
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kafka@sha256:52f275ee1254c1807259edb926d522612afc2c53c7df31a22c0e72d0520404c9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kafka@sha256:3ff1333304ee50bbe41c8000ea02fd2a44ea542a7d80e40e9670c43baf077ff6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kafka@sha256:f38827ce863ff958b265eb3438da3cf825f87f279d6db0929768b4755b5d207d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kafka@sha256:0b9eadf89b5a24c0a6308e56b573ba09ec6ddd07f528bfdf6841e3022016f6ec
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kafka@sha256:adf5c00e379221d5064e03fcd6e76df0281848e574e03decbe097b2c1ae66899
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kafka@sha256:fe165d670dabd547f35380cdce622e4bec24d81acd1e96f7394600ac2c7b6022
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kafka@sha256:76727eaec21d22abfb268809c5571b2d9229fcf22a724dc11d8c3408292bd7bc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kafka@sha256:e7547921041e811e51714174dd17eec29bc97e472b6149f062ca8e0143079423
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kafka@sha256:d058045a51ced082417fb5a7b0b56769beeef9aae617c115783e64b2539b956d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kafka@sha256:f93fae168ef3dfe56ea625b1f67aab6093638af6e5e7682f1683a55268eb44cf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kafka@sha256:53a4a7878fb0e35c342350f4a325902eaa793d14ad195431d6516d14f3e9cf5f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kafka@sha256:7dd0076f0ed6791ff865b58a90cb9b6542a3dbbad890b6f7df836d522e692dae
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kafka@sha256:be7bb217c3842c28f09a872c1a200bfbdf475386f4ccdf61cb5e04ae4bd13d31