Sign inSign up
Kafka

dhi.io/kafka

Apache Kafka 4.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4.3.0-debian-fips, 4.3.0-debian13-fips, 4.3.0-fips

Index digest:

sha256:13add5964dbd1b7fe09dd90f23ede5b56cfe6be8cae58c541a27cddb310ce996

Manifest digest:

sha256:5afcd880bf1bb94cb47d55327ed82528b8ad70839d3b8edb0ed015d64e6d1dc8

Size

197.15 MB

Last pushed

2 days ago

Vulnerabilities

0
1
3
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kafka:4.3.0-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kafka:4.3.0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kafka@sha256:10fe2977ec5b0116ca221c7cabe390fed7eca185cf88604e0bbecba80e2b78a2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kafka@sha256:9060a9e44cb59bff95e2feb7bb260a6d8e6f9937e0c19a2c6ee9bfe58698f5d7
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kafka@sha256:d53c28bb6b9e25356a9b43a3a6596da20dd9151f1163a08b370c93ebe4f580d2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kafka@sha256:c1b0e92f64afbf909f9275996e0223498430a750fa37f44eb109e7e448a4196a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kafka@sha256:e5effb1efdc546e7e2d2d23a0b464d9a589ccee79627a17143a29d6d7632292b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kafka@sha256:ab563fb5cc49d7e6aeee9b4e3facd3a9877d06669b69b0f8d7b707c830a9fea7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kafka@sha256:9a1653e401886674abb3b893ee39c8e109f7a8df484c83e26f13a595d38904a5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kafka@sha256:16b635969ffaf2c91fea3a1b14ad03e434ae8dab971921fa93494683372d76d0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kafka@sha256:47f0a00eeeb26e694dec2da964cf859b7c4db1db36157d9d82b43777943f8a00
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kafka@sha256:995d050e6979d7bb965c9707a09220ac2f793a6f907f7e4c5f08ed23da9ad01f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kafka@sha256:695fc9e9c4e3b19354ad3b61803bfb7660abc744e61bc7c49bc1dd796f45dfa7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kafka@sha256:5d45c298087e96e9aafd5f82dd9bd78d7d5143e29b4f9be6e26bd7172c3af2cf
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kafka@sha256:d7a983880f26fcea0a450bb8072be2ef12602f5f611b3148885ca4d2fa5d253d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kafka@sha256:02b417edbec81584b8cdd37d9424c37b58f67fb3e6b9652cc03b19a2dc0c4e80
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kafka@sha256:aa605b6ba68b793865df17552b55aafc112c645233a6b4ab2d293209cd231243
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kafka@sha256:90dd65f2d4a108805b1962cff9e8575982f8328a4bacae2508d71463937c6565
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kafka@sha256:ccf536ca885090c362f2c8b0d5c7a3f22fcf9656a61fe65608e7dbfa77db76cb