Sign inSign up
Kafka

dhi.io/kafka

Apache Kafka 4.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4.3.0-debian-fips, 4.3.0-debian13-fips, 4.3.0-fips

Index digest:

sha256:72030c0d30a9b1a03ed7387055656ed3d05d7f9cda6ea108b817f7f9e7cbb15c

Manifest digest:

sha256:2d5f5b7043debcaf96d0364bb57d281b895a591d8149a501c4c2d0ff6ad96e0c

Size

197.15 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kafka:4.3.0-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kafka:4.3.0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kafka@sha256:722b1070675c206a413ff438e7cd6c76a3c2b041cc0b4918fde6852cadbf3666
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kafka@sha256:a9fb8f95bc9f0c4acb8443fde07a62234b35d5751068b268dfc908ff96e7a15b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kafka@sha256:b02f69dcd6c1cea8d4f8bb090e28ec6c32087b036a3ae345b6d6834be1d09033
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kafka@sha256:4df15a7b54ae2cbd7ae74e68d91dd9b79772d8c0416c4279dbc52bf841db1210
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kafka@sha256:f893d6bc1d55772630c60e181cfd6af0e5cab1f26e40ea92095641922e29505d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kafka@sha256:b2b04ac23a790418686f3aee5dd5992843374c2c43a350ada3f472efab5dec38
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kafka@sha256:a8fd26aa0731c88c751dd5ea05fdb3a5f0026412eda515e804df95e490a5c18f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kafka@sha256:73dfe8544863c3298709983c179fabf8045b2e9109c0ec2f017f00274272bfc7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kafka@sha256:9156d5dc52ea99098d9a8907b2d2dad5fcb8a2ca44a9ba61b0c3270237d09384
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kafka@sha256:6130c016110993a21a155dc979071e0afd9842ab731b52760ff4d4a430d0fc7a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kafka@sha256:dfd92057a0d40005a0e36ac5febbe5fb338992a84e39ddeb724d4804346859c7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kafka@sha256:3b8164cec3876c3c9092b82e012b70cf71831a711cc9c2ee16a705dc7f20e006
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kafka@sha256:4ddffb15f2570fc6f62614dc760bd2a35ebfbbe3f8cd3691a45a2a6dd100aaf7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kafka@sha256:b3bce8974b684ceca54a8882f2d49dfc3e2577347e6dd8c571c1632ff6897986
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kafka@sha256:e721f92f5ea458965638cd465de0ee2f01e7ce7ebd67c326a1f19a6ad909a8e8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kafka@sha256:ae80bb97e2ba9a09431e29ded56b342b9df66d4fc1582220edf6fbf2eb0c895c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kafka@sha256:f8a0f861f51b84c1cee3d4413863ff4e9c77bf07c3ac0ae203c177c613288548