Sign inSign up
Karma

dhi.io/karma

Karma 0.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips, 0-debian13-fips, 0-fips, 0.133-debian-fips, 0.133-debian13-fips, 0.133-fips

Index digest:

sha256:e649785b56a9606f0e52895ef3efef86b0ddd5e56fc38cb5bdeded069ef778ad

Manifest digest:

sha256:f99a97ad1533563d38ff9ee491d3c380330d72f42349cdad5ca940b9d285bc90

Size

15.79 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/karma:0-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/karma:0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/karma@sha256:503c444ba422a07dd8294820318c4e3c1eb2c6c46901cdf050e307eef43963d4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/karma@sha256:ce3a43d69b9e782d92e88e998cadf2c6dc3c6d980ec27acf92c15390ee4586c7
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/karma@sha256:07d97a37fcb465d879d159bab6de28355e5f8b747139d83a3c0be43493d146f2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/karma@sha256:a099966b7f160cb63a70504f3fd0e6567df303969f431e93beaf0645d363e55c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/karma@sha256:a0c25dd0a6fc509b55e5a3f02d6aa4a24750d892642460ad3e0ea29762fc41d2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/karma@sha256:2389d0144b841a073bd2df92ac9d38f0d084895bc22b7f73baa098ab7c0be4aa
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/karma@sha256:5b74830ff5c49219a14d1251ef4228fc24c13f4ddd0f746ff09911a1274413be
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/karma@sha256:0e841f714f200d830cb22dfcba1506468eb997a96ceba421772be493f044a5fa
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/karma@sha256:b904f5ca9001f3294924fba88f0976d97084fbd19f5fb9b89fcc3f3ecf999dab
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/karma@sha256:d37abfed8c385b5963342a2825919a0e3cb856a21f0dd09b913581c580a45b1c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/karma@sha256:a0963b48ee687c6c22d7df91dc16e55be2edfa8bb21db8dc8dfd195a12551bf5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/karma@sha256:1109249a6a3fc1a265b770d90074c673dfd14049ba404e4d33e2b342b76d046d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/karma@sha256:1b972eee9fd305b75198e3b535ea19b3e68367e28292b64cc802828089fc5dc7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/karma@sha256:319a42e6f8ead0d4421db0ba80ea86f7078e41fb2be9458bf3c29f7e4e4571e6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/karma@sha256:acc4087f02f0fe3b3af7530e87ea9511b78a9e9c3b7bdd2f1cfc7fb91a8b98c7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/karma@sha256:39b2ab39626de5186ad311517c930ae14b056d891163c0ac08d7bcc2eb203afa
SPDX SBOMhttps://spdx.dev/Documentdhi.io/karma@sha256:b28e1e511cfb9131eb4850285147e43e455f555586d49b35ca104915e12f5b16