Sign inSign up
Karma

dhi.io/karma

Karma 0.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips, 0-debian13-fips, 0-fips, 0.133-debian-fips, 0.133-debian13-fips, 0.133-fips

Index digest:

sha256:7cf638ea6a3c8fbd602a7f3986885bcf7180fb5eb6a05c6a046a4070e63a3d51

Manifest digest:

sha256:13f948b76b1fc2a2e661f82afa2f583ea41c699387ea136da4d8742c7ce2683e

Size

15.80 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/karma:0-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/karma:0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/karma@sha256:bf281e20c0fbbaf1d55d0d2f12d82637cfbfd3468d1f033f69785318671ad752
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/karma@sha256:cd7909f5306d6e76fc10238709ee08903dfec10ec2f55043914dcbe6eed1ec33
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/karma@sha256:092930e31d40e8068b3120552d43394f1fa89a7592166c707e8a2bd2a7995988
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/karma@sha256:9ed07272d40246120a9de14c9cc05903a8df75f5e0f38860f4f82554d4500a75
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/karma@sha256:08dbf0336ce40e84552e90453b48d5c40032a628dbc374156ed4cc889251a237
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/karma@sha256:751e822ee9f0f53c73f1dcc3f109cb94f10def46e0c31cc0658c1dae6d96e17e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/karma@sha256:23575163c4f4f35758e2fa6cfcc783acc78a99ed423c0a950835efef383502c1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/karma@sha256:ab30880f5293226164483ff2c177c540e5997cd0e1dd7574084dda17313bf0f2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/karma@sha256:e36bad4ee1c65925a806ee88eb1969bed42f064c52454d23163a85cbc630fdfe
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/karma@sha256:896f413410748b59663e3334d835e0528c75cee752e423f361387cffe038921c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/karma@sha256:ee10e681535d20d3226cce45bea685f5681715f064502b47a9d773649ef06419
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/karma@sha256:012346d2dbfbb55f6587a581315fcc6b3e1c91eb16c3c51de1a87cff1bd04fff
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/karma@sha256:6adea367435a2cdfaa5f480fc887bcc4ae4042e6f71e974f783cde38ffb34de6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/karma@sha256:7ddd720351365a956ac75232b5026e8b4c631cba1cc96a2165cc10ba258d6d01
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/karma@sha256:661ff3d62aa45a12c4723f54265d58db0675482fe6c4e7a0caa4dfaccfceec37
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/karma@sha256:1df66585d418c2bb51d583ebe51e9e951af4ac2e8555fbe8fb856bcca4ba4367
SPDX SBOMhttps://spdx.dev/Documentdhi.io/karma@sha256:8b6f90a786d61f60992cf8ea22443a3238df4b21b79a1a50f159a8048145c483