Sign inSign up
Kafka

dhi.io/kafka

Apache Kafka 4.3.x

CIS
linux/amd64
debian 13
Tags:

4, 4-debian, 4-debian13, 4.3, 4.3-debian, 4.3-debian13, 4.3.1, 4.3.1-debian, 4.3.1-debian13

Index digest:

sha256:1f26e0114e02a64928b17e2d64c01039a89c9c3d3d8172f08645d3968fa785ea

Manifest digest:

sha256:1595fae2cb508fe50b0662bd7ca52ad85037de65600adc365320cc29495809f2

Size

187.44 MB

Last pushed

20 hours ago

Vulnerabilities

0
1
3
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kafka:4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kafka:4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kafka@sha256:3693f4061440b45eeaabea7382d9fd1fc8288dd18f8a4e983037ffab29ff5aad
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kafka@sha256:9a06f0b6dad0305629f362380d71d8f559515216cb27deb7e575533d099f0629
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kafka@sha256:3cf5269aaa3c9f0af53879faabb29a3d24501ff156ef49e30e7de76080e78980
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kafka@sha256:01eff42ad3b5e0829d9119470704743b4a0978e1c8b96a4b365603ef68b37cf4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kafka@sha256:ade674c78b64d07b27f1b08af969ff855ae1d11ecfda0f44ba02b02882e75ea7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kafka@sha256:5292653cf22bf5fa65cf1610797a1fff06e4e110a3f18922b46aa084fd1e14a5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kafka@sha256:146fae7e79898ef5b2c4e29085aecb68b42dbe572c58334046ed4f5383124f5a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kafka@sha256:c9dffc8baeb0e2f91b0935352b7585621d21d14a5970f2f96ef90f456e6c8dcc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kafka@sha256:4d1f11fd30edae6829b2a36de5c8ad5b5ec83b9889b1fdfab07f11171980b4f9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kafka@sha256:37d43eba8bbc1ecd180d109fc7614681574d8cc43c47d075ca4ed60e7d3ecd24
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kafka@sha256:8609c9d354ce1418f3e76f3920401eac2a41b19fdfa86bac3c856c48e8eb6944
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kafka@sha256:c3fc1ff0e2929aeffb52d0370390b883c1757d48853300c2e5a4fd4dc1401333
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kafka@sha256:e2538d9f0acf9ccd45cfe46b4215d7ad583fa3fb5f98ab10f0aefbd329cc75bd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kafka@sha256:18bdb652ee4769b0da394b401d772037981c72bbc8b14d8980f46f70a4dff1a9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kafka@sha256:9e42d62f9fbf04130c246210a2e6ef584a9bf87e2e311b29698c86d29097d5a8