Sign inSign up
Kafka

dhi.io/kafka

Apache Kafka 4.2.x (native)

CIS
linux/amd64
debian 13
Tags:

4.2-debian-native, 4.2-debian13-native, 4.2-native, 4.2.1-debian-native, 4.2.1-debian13-native, 4.2.1-native

Index digest:

sha256:56de9fc63b145afbc7918ae4a59336717943ee6a969de4e896469d470004471b

Manifest digest:

sha256:75bd66f3a9878cb7cebbcb295545cd8eeab6fbf757cde50592cf82c59b5ef88e

Size

49.19 MB

Last pushed

2 hours ago

Vulnerabilities

0
1
0
7
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kafka:4.2-debian-native

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kafka:4.2-debian-native --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kafka@sha256:3a888653f28fb78e6242a4afd4a726e4f9e0e7b194d72caed33043705ea7b61d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kafka@sha256:55561b7ff3ca64f1374359a0a53167bcb7d98d586f5c44ca4349be5cfc92378a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kafka@sha256:2a1f55c6949fdd544b9a57a871e9518787552e33991cafec95442a9efbd259a1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kafka@sha256:f43dfb9b2013bab05bfc652bd73d7af8442677a12f62874546b0a55008c738ef
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kafka@sha256:e2e255cd538a08198e5a7ea036af19e8fb9d1d614fef13aac313f02cea328540
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kafka@sha256:e113d920540e13723f208f2a73d088ea7a6490e5a844952fe59b64afc0c971ed
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kafka@sha256:48818a8cd8c65736bf064e5c6bf175cb9000496ab97ef242de9e83d6cc9bd4a9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kafka@sha256:54cacae0446923d35dc0a7728b809be6b4a63997b07b315b14045d823e6efc42
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kafka@sha256:daa439507e1616134062180925977a9423040c162d7162ba9d05a02503462c73
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kafka@sha256:3a21f30fab4747b93086ce9e73d3f944afc40da5c429e4d38dffb614ea813f19
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kafka@sha256:f5113b07cdc658a400bfe4090a444066b63bfd0a48504f30a160947dd1c43a49
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kafka@sha256:c9d5c98edfb2e7922be67ae2b3a91d20c27aee8881c623137e84b7e15a18bba5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kafka@sha256:786584926fa5a7a875545db2f6c6fe3d210839540c1194f008c40b1687d88074
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kafka@sha256:3a66d08ab6eefc027931ff745c8109b120fee0238429a7255d850f9d78b8ebcb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kafka@sha256:09e11181a9f5dbc8ae3eb23079fb300057bc13ee13b07fc7e9810fceaddd696f