Sign inSign up
Kafka

dhi.io/kafka

Apache Kafka 4.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips, 4-debian13-fips, 4-fips, 4.3-debian-fips, 4.3-debian13-fips, 4.3-fips, 4.3.1-debian-fips, 4.3.1-debian13-fips, 4.3.1-fips

Index digest:

sha256:6db0e654b3a0ef9338874407ded0ce147202efd14556ba06202c01fd6ee20515

Manifest digest:

sha256:e97f4ff56534bc1715eedfbca6a0d893a4d65bd565f10687fd87a151bef0d539

Size

191.83 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kafka:4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kafka:4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kafka@sha256:c3ef0878991fe3bb0b145a50599134df5f8c5d73298654da01e171e3475d25fa
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kafka@sha256:cfa5bfc02c0c5a46d4494ccc5b4abde7aebfbef19c7d30432b08e85af9f307e0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kafka@sha256:9245c4b23ead2b525b7e0958d434262aaf4b0a664cc54cfa2c255b50c8a2678d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kafka@sha256:0e8b718a8678e663354e62a3d24dbb5baa5973f22b3b2f1a2585e4ea6945e688
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kafka@sha256:58a7496229f718eb308987bfeab71cacf1586c657114c8e449cd1a079fe2836e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kafka@sha256:948b39593073441f6139d58c5feb3c0d42e61a4eb9e185532b4a2b574a8d6f2d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kafka@sha256:91d6397630c98bf422c625544f0cb1ae05f38fd04137844228953c108e5e7d99
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kafka@sha256:6bc75fe7336016f0be7011db4ef37c4f5ed5d82d2729433ee69bfe0318a7609e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kafka@sha256:e7c61205dadb046f0723c2920bb7fb5180b62035e5edabf60cf62b9b2e382fe3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kafka@sha256:2be5854a93ff64b5270d0c1907c2a07e5f24492a8f02fd793f0e85f6d0818a71
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kafka@sha256:2358ffa989f6970c48301d0b0b281f83b73260e02c0468472508b63a277d0f77
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kafka@sha256:d6c74ba08a3a1e9679baced00f00590f42cdc0b6a2fac7af93e3d9a27b3b3e6f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kafka@sha256:ba5472b5a8f81c9afa2cb5a280152d5cc153bc543a517012dfd9b09637a3beac
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kafka@sha256:971ca8c4c08e2b2f71b12983629858d9f44c66048d45afc98ddb79a7dd87b7db
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kafka@sha256:a5e51caf9c06e1cfdbc54c37aa802b22564a75d244d6e8c3e426fcf2df41691f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kafka@sha256:09eb02c34644f340a827e3ea240ee08260ccfda8ebfb8a789cf9c7799623aa84
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kafka@sha256:bb9865421226756d3d654b6cfa1a206edc768a0f9fea81b5ac3413a0ee498d4c