Sign inSign up
Kafka

dhi.io/kafka

Apache Kafka 4.2.x

CIS
linux/amd64
debian 13
Tags:

4.2, 4.2-debian, 4.2-debian13, 4.2.1, 4.2.1-debian, 4.2.1-debian13

Index digest:

sha256:02f131e608d463d8a85b5fd9d1c376870be2475dededcf107b9bba4a0b9abf7e

Manifest digest:

sha256:5f9b39b32d8aea41f787cd27b32ed800a0ba18d7dec069ea379259b55e59efb6

Size

187.27 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kafka:4.2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kafka:4.2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kafka@sha256:3795a1bfcdcab2d72adcae9b5aca68fb0f96fc1b049a2b4a391384700fa82b0d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kafka@sha256:55e2a6a4e2e5e98a41e835bc0e6002ee25b0f10ed4b2ad2b38cb2460354e04ba
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kafka@sha256:3c088e36ba7b56b682e5324a4d8d2b04f9a971c6fccd48a94455a8cfeae0c076
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kafka@sha256:325ed2f1c7751ea35f8df09c62235723d71dca52170f80ca2c71e5cda20010d9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kafka@sha256:5b4e10a2e089ce41428cfef317019d5d2e8b2403433920f28a3000489e130972
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kafka@sha256:9dccb3c44f6c11ba167edba6f7b18ab9cfde185225e403f61d3455589865de91
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kafka@sha256:3e433ded45ab08927e2268862b5222cf4b763a0a6b16a4bdba4e4f1d5a2bec9c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kafka@sha256:782b9fba3f158148e2b3fbc752dc165916b4e90201706bc001757e887c15fe69
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kafka@sha256:680564465ffe5cc608bfdb5768adeff07b6f191c036845b8250c77fca1e19e42
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kafka@sha256:f432af7220b74f8f1fa184829f420d0e7b52daff92bc696caa6c0c01d13f3e7e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kafka@sha256:048e8ec239ccdb8c614eb9f7a85a0e0e91228b6fb8bd0a41763a19a2be3f71ff
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kafka@sha256:9353b9c369692f9553c7832ac5807f27529ddfc6c2c05eaab6a8a7143b3d1531
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kafka@sha256:4fcbcf036c8559fd08a55bdd7a1d10ab5c977953f9322e60363be7fea9c6be83
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kafka@sha256:590890501ea45e2c8bf9f34b833cdd5ad48b07970fc9e777eae0170bfeb737f0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kafka@sha256:57293e9fb95c02b4a5f1b784ee5096e9edb445600d205c44df56e996521c7e11