Sign inSign up
Kafka

dhi.io/kafka

Apache Kafka 4.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips, 4-debian13-fips, 4-fips, 4.3-debian-fips, 4.3-debian13-fips, 4.3-fips, 4.3.1-debian-fips, 4.3.1-debian13-fips, 4.3.1-fips

Index digest:

sha256:fc8e739d413773e94a60a53ed13c0c9a6dd7d4950b2c9701dc2b4a6ae7ed2391

Manifest digest:

sha256:d66ace589a4849592a45ef6b4945bda261fe02bb0a87b4101488620017d3fef4

Size

196.56 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kafka:4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kafka:4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kafka@sha256:22bdd80b522a50b032a344e235220148568adf7e31a12582bf62dfcd3a6ad843
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kafka@sha256:f2f05e3797f54034e1cbbbd184624b44040295586fc2e325a17082a87f58e8ab
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kafka@sha256:605a106d63750bc0d5221b3c519f28aa36c8fa751d20743aae8ebdcd2a77872d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kafka@sha256:e98ce031315293f478a537d5b61b0aa322573f7e379137a0a55ba23cb0109f80
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kafka@sha256:81be63801d75625f0b75b796e92e60cb2200def431a64434048a5fa08a42e4bd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kafka@sha256:6c736ac57074e531767271802e797fbbe857c0f3b76d3844a107e18ad551875c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kafka@sha256:25279f8cce7d754bb5594e576619b47c68dd9307940fae12b4aeca17df6944f4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kafka@sha256:7c633e63cac50a4d59506aa65e94c4e4b8fc2a5ff96ceacc1e53441817b43b6d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kafka@sha256:b20154235ea50f536be54a813a4acc1dc47860ebf54ec815d7094af179d3d513
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kafka@sha256:05c371d3f5390be5f9aca711e19a38634e07db5db2b0c1377f73b09769e9b323
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kafka@sha256:b3167a52fd8905471049b234a5cada3efe6200b1871d3125168f9e2df35c6cc0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kafka@sha256:cb1621f33bf71398d59b5ac1ef5693ac353cc630e6d7d845492d10d7a6437fc9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kafka@sha256:a4986216a7f40757f90c7d43f7c5a5ff0546ae18d84c9e4c181eebbc749b9410
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kafka@sha256:d3cba2d8a3074361928a7fe4acff490150e7bdc88f0ccf956d06127fc8b75ed6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kafka@sha256:c37c012e34968dc25d85adedc7f47221f0d9683e2e2a463986342d22295d190a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kafka@sha256:c43b2e463bb3ebd4f3ad45dfb5ff72b35ada2671fa0f062a218cc3151a95a1b5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kafka@sha256:00a5441d31eb72729faf5ae8482ef0c53614ac1cf6f44ca840a2ec38c33b0aac