Sign inSign up
Karma

dhi.io/karma

Karma 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.133-debian-dev, 0.133-debian13-dev, 0.133-dev

Index digest:

sha256:5308c7e30b45dfd4c33b473429ca4bbd506795b6cad0bed49ab914537e554c46

Manifest digest:

sha256:5b0ffc4b59efc63f5e393efcac227991c41493a61fcf1341be6417089f402b2b

Size

35.81 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/karma:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/karma:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/karma@sha256:d7fdfcf6fcc6e5f05bed149e26dcc585d14ef76dccb620735788c8279408f9ce
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/karma@sha256:b4eafb6394af1ee997aa9ab7e2bf56106217b9987ab72265765b8349cf80f603
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/karma@sha256:aa19b7b96ceed93d1f3551bf2be443ebe86d868fd13987ec2e1c3678e64c73b1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/karma@sha256:7c8b479c64136f9f8f9c285283a3d82a99a4f3b0433508ac9fd366b9a469d59d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/karma@sha256:24c647ffff2ac7d279bd73c280904ebf0784cbf43aa0042d4bb94d5801f9e535
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/karma@sha256:37bed64c811d5c5cad1e9a28d5bbf7a5016d3e311830d4ddbe283306030f7bb1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/karma@sha256:f8924e9ae73533abef368e8d71d35f9d5b169878dc1803ae63175658967f83bc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/karma@sha256:ca10769351e0cb054514224a75b66fae5fdc1224561e800e2cd25243c9073c80
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/karma@sha256:afdd2713bfc9cf318db23934f466e5f59af40607ed548e293fe794088910edd8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/karma@sha256:9f23d78e1f4f5a4ee4b0f371b5a82a3bb300e929561cf46b625ffc0ce377e028
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/karma@sha256:d13e65038079f17c5598ae2e29ce89658fc75e3269cace0f8ea1b7361558eb6a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/karma@sha256:9b6944f6b4dd63ca1ebcc4a9c4321e2363c2f16d05663a544e9918fa42d54893
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/karma@sha256:138e71906287c4f0ee0afc2955bf6c00584904c08a031c2968783f244b3230d0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/karma@sha256:fd5d6fe17e8422c3daeb4849df37073edba1d029362a3bf0585e111201debeef
SPDX SBOMhttps://spdx.dev/Documentdhi.io/karma@sha256:41af1ee48c2787541fcca286a83e3ae0fe57a447a93526f4a66930bccbf99654