Sign inSign up
Kafka

dhi.io/kafka

Apache Kafka 4.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4.3.0-debian-fips, 4.3.0-debian13-fips, 4.3.0-fips

Index digest:

sha256:9395add3eab1bbee295526d5dd5d3545edc850f882cb8c0ee4c51647df3cd954

Manifest digest:

sha256:ec8fda8b0e0bda692c94acc9bb20c81abaa57bdf75f5b616d80fca9e9e9d97c6

Size

197.15 MB

Last pushed

16 hours ago

Vulnerabilities

0
1
3
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kafka:4.3.0-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kafka:4.3.0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kafka@sha256:edaa1b84b6b5a6c6b7f0b9584b4f3e3b7bb588c503c4a7eb9f490a93a04baa4b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kafka@sha256:e9a7abc560998c612ff03896f18258233052200a183ba08384139d46c762efe9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kafka@sha256:428b254ddcf5e29802294cc4d1f84aaaa3639ad06980bb5b0b35e86e108a23b8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kafka@sha256:980db3279c99dcfecab4351081b7f82247f281bb198da076583acf10a8676800
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kafka@sha256:99f8bc309ba48c76bd1d6c44609731084fabfe356bffad153209dc83d8284078
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kafka@sha256:907cd8995689f3395ed0e4943ab9581a8823dff303222d447e1949e41b85d3b5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kafka@sha256:0a4dfd6a2897dafe05f01e558a9b9c1cb5fc705ee485459e301c4b243ef8eba6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kafka@sha256:d0e87e7e7e9a0897e31e337118dacf34afd2ef05f6f8f5f22c5d5d3511a1ee3c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kafka@sha256:f67c2cab7cec307f08a74d7399d4c80563036de23e86988f933c5c1fc52887dc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kafka@sha256:d4d6e6515a7ce9a4ad96ac6bb57f8079bb351e0876e0d55dc117cf691bf57c94
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kafka@sha256:3c0189a56defa86c5089f1c64037b57230565662c70577661caaadbb9034b355
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kafka@sha256:2eec9f8f79069f7fd1f26695e6bb45261af5e85b578712fbe8820a16a3a3ce00
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kafka@sha256:814de670eff7fa28f284382650d3cb06500ade53b78cc019346854abf7a3430d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kafka@sha256:5a5cbbb3b4519624d8720e9321c32a1bb2151aeba2a22250ec9a96aeaf1713b5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kafka@sha256:ab702a152d8f36bf7b3eddfbbb3ff2efd0f00f12b925abd4123ea4b08baa40e2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kafka@sha256:5d9e4085cffbd74e3f4342a0d15717ecd0c200a42be8fc01c165790b7839e2d9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kafka@sha256:2f03131038614b86872c08308e5545cbe3b6910fe998cea3cb3a0c39974b2b6a