dhi.io/karma
0-debian-fips, 0-debian13-fips, 0-fips, 0.133-debian-fips, 0.133-debian13-fips, 0.133-fips
sha256:e649785b56a9606f0e52895ef3efef86b0ddd5e56fc38cb5bdeded069ef778ad
Manifest digest:sha256:f99a97ad1533563d38ff9ee491d3c380330d72f42349cdad5ca940b9d285bc90
Size
15.79 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/karma:0-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/karma:0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/karma@sha256:503c444ba422a07dd8294820318c4e3c1eb2c6c46901cdf050e307eef43963d4 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/karma@sha256:ce3a43d69b9e782d92e88e998cadf2c6dc3c6d980ec27acf92c15390ee4586c7 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/karma@sha256:07d97a37fcb465d879d159bab6de28355e5f8b747139d83a3c0be43493d146f2 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/karma@sha256:a099966b7f160cb63a70504f3fd0e6567df303969f431e93beaf0645d363e55c |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/karma@sha256:a0c25dd0a6fc509b55e5a3f02d6aa4a24750d892642460ad3e0ea29762fc41d2 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/karma@sha256:2389d0144b841a073bd2df92ac9d38f0d084895bc22b7f73baa098ab7c0be4aa |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/karma@sha256:5b74830ff5c49219a14d1251ef4228fc24c13f4ddd0f746ff09911a1274413be |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/karma@sha256:0e841f714f200d830cb22dfcba1506468eb997a96ceba421772be493f044a5fa |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/karma@sha256:b904f5ca9001f3294924fba88f0976d97084fbd19f5fb9b89fcc3f3ecf999dab |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/karma@sha256:d37abfed8c385b5963342a2825919a0e3cb856a21f0dd09b913581c580a45b1c |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/karma@sha256:a0963b48ee687c6c22d7df91dc16e55be2edfa8bb21db8dc8dfd195a12551bf5 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/karma@sha256:1109249a6a3fc1a265b770d90074c673dfd14049ba404e4d33e2b342b76d046d |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/karma@sha256:1b972eee9fd305b75198e3b535ea19b3e68367e28292b64cc802828089fc5dc7 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/karma@sha256:319a42e6f8ead0d4421db0ba80ea86f7078e41fb2be9458bf3c29f7e4e4571e6 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/karma@sha256:acc4087f02f0fe3b3af7530e87ea9511b78a9e9c3b7bdd2f1cfc7fb91a8b98c7 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/karma@sha256:39b2ab39626de5186ad311517c930ae14b056d891163c0ac08d7bcc2eb203afa |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/karma@sha256:b28e1e511cfb9131eb4850285147e43e455f555586d49b35ca104915e12f5b16 |