Sign inSign up
Karma

dhi.io/karma

Karma 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

0-alpine-fips-dev, 0-alpine3.24-fips-dev, 0.133-alpine-fips-dev, 0.133-alpine3.24-fips-dev

Index digest:

sha256:61d8e9795ba23c494a007e3eca3dded0d7e6ddec0aef611d6f741a224feee133

Manifest digest:

sha256:53b821668e6db0e932afa1416ea0f6fb90dde445bdd39703963afbf50177c62d

Size

17.06 MB

Last pushed

4 days ago

Vulnerabilities

0
1
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/karma:0-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/karma:0-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/karma@sha256:fd2dac4c1641d33732a40391224eefc927059c148859e8ba75605b5f409179e0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/karma@sha256:9a7fa61fd5903ad44de0477919681fbbe33bebe5d0283b5d18737b8399dd5031
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/karma@sha256:a6447c5453dd4d5f1b9162b60c7d7cdfa2bf025c83091fa8d745cc60fad1a5f9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/karma@sha256:78e408988790bac862411ba1ec62f29b07eed88c03e7606f931ed9ef4577af11
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/karma@sha256:2dc0cb0d4ff9d9cf9d837e27cf3af6f0e58b3ec894923cb3c6604e4a04c278a5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/karma@sha256:a6625ebd683076a15332f08cc359e139a5e9b615b53e3153e0c7ecea61692ec9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/karma@sha256:a5854ca7561498df69663c004601bfe4c28799d0838c3d7f3762066cf29748e0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/karma@sha256:b17f3a457ce305f348f2a0a6a81ad37c3e7977fd0d458d633de3381a6438f95b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/karma@sha256:9efc629cb7cd66464518834396329ec160fc9aee9e3d4514628915d18e4ad01f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/karma@sha256:1b74d7a1da70d4ea421744d8a73f96a59072c026ba2469dec816b9b8d99590d9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/karma@sha256:31221d5686f7f4f65e541bc12be80f3a07867edf14a9746f7b5e6121e68ddafd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/karma@sha256:45f1760799e6ba163cbb1300ae2c196ff937d6dcfddac92f933930a5157313ea
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/karma@sha256:fa35642f9007fadd4f75206f6f74de8d3ba3de1263ea219eb5c9751732cbc03d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/karma@sha256:f37d3b3f50a24a41f1fefeedda9b725211968b1d140d596c2e5eead36152fd61
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/karma@sha256:28d9ee602e35c2a3ba2ac49946f08ffc049d895ba34666e6382bcd83bb044506
SPDX SBOMhttps://spdx.dev/Documentdhi.io/karma@sha256:855be1c430b5f96335a2af587e1da1927bcbcc24f705d2e7c297e4813575570f