Sign inSign up
Kafka

dhi.io/kafka

Apache Kafka 4.3.x

CIS
linux/amd64
debian 13
Tags:

4.3.0, 4.3.0-debian, 4.3.0-debian13

Index digest:

sha256:bab26cc38bfda53da37b108ebc7b9c778b5ecd31c949f2a2d512dd77075019cc

Manifest digest:

sha256:dfcbab39e42efb2e45340a2b7235ce2367aec093bb6724ade5ce0a46b4a03eb5

Size

186.72 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kafka:4.3.0

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kafka:4.3.0 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kafka@sha256:881097845a49a108bcf4394d7365f544e98826ff98fbc8238e80a5d3ddc99616
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kafka@sha256:a989fec4441cde7112882d875ed0f45f197362aa96e6c44d800abbf5b43d6987
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kafka@sha256:9788a515053d890fc54a35ce8068122b8659c9cb2e6d8d87f5d273d935e04c49
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kafka@sha256:c976e5129d3996891ac7afa384da09122f7c63a64ad9776b4488ab85095595b1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kafka@sha256:d84b5da3659780f9412ad96aa5af73d352cd038fc1b4f06f4a5498762b50d4d1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kafka@sha256:cfc959f216737893a64e1c6f7fd9b051d3b36e6fba44a5303926bb31f3b0b13a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kafka@sha256:43eb9124654f9c83a3f6416b0d6216e457c0f013ee02d551c81b34ce892692ab
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kafka@sha256:9231477f5e0524165cca892be8807b1d06225534f4b73eb8c4b63d2d62d040c8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kafka@sha256:554f3f4f531169bc9f58aeb95ae4b7cfdec867386cb67b82a4d01fb6e7396a81
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kafka@sha256:abbabcd910cda83def8ece805a6e15fac34d72b3831a2ae927c802640c982788
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kafka@sha256:c5cf84bd1b3d46e25ff744f64d5d6c2f86ec5ccd9b2d47399700f2b49dde04b9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kafka@sha256:0e909fb30210419197f48f894ec2be8ccd8bf46b3792530b01d4acdbe037858e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kafka@sha256:9872ccb065051f9e60a5b6e450250938c87f7864b136e3a4d38ec253e43c54ec
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kafka@sha256:51e737cf2cbd1ec964814defb697a9bf7017966dd0ec412cc58654488dca5215
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kafka@sha256:9ef0c0f5b82d679cef45a59ce603c8bbd180a414d051a370cd673f6bd0167e23