Sign inSign up
Kafka

dhi.io/kafka

Apache Kafka 4.2.x (native)

CIS
linux/amd64
debian 13
Tags:

4.2-debian-native, 4.2-debian13-native, 4.2-native, 4.2.1-debian-native, 4.2.1-debian13-native, 4.2.1-native

Index digest:

sha256:3035fcc778e8ac1a6a32d15ce7c50b07e2812fee1b67826e4eb2f97cf002a525

Manifest digest:

sha256:66ac723a6d21c625e7e3253b6b34b6592cfcb77f03220014586c6e0e0195c24f

Size

48.52 MB

Last pushed

2 hours ago

Vulnerabilities

0
1
0
7
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kafka:4.2-debian-native

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kafka:4.2-debian-native --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kafka@sha256:e08b469c200bea8dd7289f770c5539ad2e81018f0b210d8b9319e8c40c771f95
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kafka@sha256:34573de21366617903970f539cddad14d952601a93202dd439737dbda5f71327
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kafka@sha256:b2135e8b24122836366de62c3cf0d83baa4d213be3174dea1fc4cd18d9446008
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kafka@sha256:de70e16c1fbe28173a1cd6034887f28d95b2711a0afb66113ede396e69315f98
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kafka@sha256:9e2956835f7036fa67c1720c81107d61802c3cd53e6a884c208d4f493aa42ebf
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kafka@sha256:df736b3c3a5d60834bf09376d8812e68fd980128d6d6f737968da95dd6a6af82
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kafka@sha256:6e55cfc9336c10aeb4f9f059f7b03946ca348b214b951c26c771b0ad68ba9a8f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kafka@sha256:fcea2241c832fd70d2c47c0f56fb9980aa326406b17245bf01e5d402d591f00d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kafka@sha256:f558fa339e9a8673c702de81ed5a31ae263cd9e3aabf0c8dc06a394f0a1fd1fb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kafka@sha256:896782ed1aefac0c455c11b41f422e849b48904be82abbadb610d512420ee687
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kafka@sha256:bbdb586fe57504dfbc6c710ef0854b1159d3f70c74465243f454a6c4ce7bd155
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kafka@sha256:d9e29fe1ec1632f2087460d3316eb121fc98e2aac1daacc099ddd0acd9848c9e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kafka@sha256:38cad47f57cec21f2d568a750ff2c523bd6469b2b4e99e6d0dcbfd92ad0ee124
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kafka@sha256:9e5b63c1da78e7e00cffec9d91e13beb2b459786ca4c23ce94443eb46861396e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kafka@sha256:5fccb03d6e514db2dab172395c3c2c09d9e652bae8c3ccd94c93271fb9d144e5