dhi.io/kafka
4-debian-fips, 4-debian13-fips, 4-fips, 4.3-debian-fips, 4.3-debian13-fips, 4.3-fips, 4.3.1-debian-fips, 4.3.1-debian13-fips, 4.3.1-fips
sha256:fc8e739d413773e94a60a53ed13c0c9a6dd7d4950b2c9701dc2b4a6ae7ed2391
Manifest digest:sha256:d66ace589a4849592a45ef6b4945bda261fe02bb0a87b4101488620017d3fef4
Size
196.56 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/kafka:4-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/kafka:4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/kafka@sha256:22bdd80b522a50b032a344e235220148568adf7e31a12582bf62dfcd3a6ad843 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/kafka@sha256:f2f05e3797f54034e1cbbbd184624b44040295586fc2e325a17082a87f58e8ab |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/kafka@sha256:605a106d63750bc0d5221b3c519f28aa36c8fa751d20743aae8ebdcd2a77872d |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/kafka@sha256:e98ce031315293f478a537d5b61b0aa322573f7e379137a0a55ba23cb0109f80 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/kafka@sha256:81be63801d75625f0b75b796e92e60cb2200def431a64434048a5fa08a42e4bd |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/kafka@sha256:6c736ac57074e531767271802e797fbbe857c0f3b76d3844a107e18ad551875c |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/kafka@sha256:25279f8cce7d754bb5594e576619b47c68dd9307940fae12b4aeca17df6944f4 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/kafka@sha256:7c633e63cac50a4d59506aa65e94c4e4b8fc2a5ff96ceacc1e53441817b43b6d |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/kafka@sha256:b20154235ea50f536be54a813a4acc1dc47860ebf54ec815d7094af179d3d513 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/kafka@sha256:05c371d3f5390be5f9aca711e19a38634e07db5db2b0c1377f73b09769e9b323 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/kafka@sha256:b3167a52fd8905471049b234a5cada3efe6200b1871d3125168f9e2df35c6cc0 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/kafka@sha256:cb1621f33bf71398d59b5ac1ef5693ac353cc630e6d7d845492d10d7a6437fc9 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/kafka@sha256:a4986216a7f40757f90c7d43f7c5a5ff0546ae18d84c9e4c181eebbc749b9410 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/kafka@sha256:d3cba2d8a3074361928a7fe4acff490150e7bdc88f0ccf956d06127fc8b75ed6 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/kafka@sha256:c37c012e34968dc25d85adedc7f47221f0d9683e2e2a463986342d22295d190a |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/kafka@sha256:c43b2e463bb3ebd4f3ad45dfb5ff72b35ada2671fa0f062a218cc3151a95a1b5 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/kafka@sha256:00a5441d31eb72729faf5ae8482ef0c53614ac1cf6f44ca840a2ec38c33b0aac |