Sign inSign up
Kafka

dhi.io/kafka

Apache Kafka 4.2.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4.2-debian-fips, 4.2-debian13-fips, 4.2-fips, 4.2.2-debian-fips, 4.2.2-debian13-fips, 4.2.2-fips

Index digest:

sha256:afd936b65f1de9b0ada84da56767a9e898807ada09ff5d19c36abe42da9f1183

Manifest digest:

sha256:a0d45c082a9da117b7e7f0314947ebf846f8077c1df66626e972afb2a6e57c5e

Size

196.33 MB

Last pushed

1 day ago

Vulnerabilities

0
1
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kafka:4.2-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kafka:4.2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kafka@sha256:4d52c56fc53de26a12616b3f510969f64019278d354b9c96c9d649b9099b1873
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kafka@sha256:c4ad94ceed62db52907586234972a5810919e2b18578d597c84665b52ef646be
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kafka@sha256:602dbf84066dd99f49869a39fedc1d98bd7d1529eb3a4de777c5d2190018256e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kafka@sha256:645a15f92c0bb2d5950b1b1971842d22e29b3eb9af2353149e650e8f3526853c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kafka@sha256:b442d510917d0015c8520012318f1a75cfb64bf3caaf006e94de1ccdedd80227
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kafka@sha256:be882a384a8d8573facf0da522143fd2fb8ff7227fb4780e94396ca8fdd549d3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kafka@sha256:d86877026a4b4ef5752d6e01af9610bdb5a46c29c2a60879df8992e0260648b2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kafka@sha256:deec71285387a570e9b725081fd5815bab04d18a8b1c120661d6620ece170d5b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kafka@sha256:035eedd04e0fe4c21578c9cabd34f966462e5dcb06bda239e4e9556fce0598f5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kafka@sha256:98d371090d3ed44407cc3899ff13ce5849bb54ea04213d68f98c92b1867a8748
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kafka@sha256:2100bdb490c5644554acf50a35b3b159e3b1698087f639fb77d272d2cb456273
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kafka@sha256:f0b5f42645f5246080480de670a4e2d84b862c92848c0960f9535c1b080ba0d7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kafka@sha256:c885f685f5f0dafcef556a51cc9f471c80bcc881100f384a3ba81c79b92e8bde
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kafka@sha256:1c88a04d6696e70824f9f945d3dbbe4cf9d441e26c0ab7500c05f0978b250bc6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kafka@sha256:4db50a7692b5c4faef2723573f04004e761dfbd43fd3fb848546d0b14b330c62
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kafka@sha256:088c00f4da53e4c882302edf09341c44383a1627c464f65b1a7f921faf66357b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kafka@sha256:1cb4c7a9bf9c0a9ae2c63c6fc7d580af097c19c42890a68c587d6f45a3ded255