dhi.io/kafka
4.2-debian-fips, 4.2-debian13-fips, 4.2-fips, 4.2.1-debian-fips, 4.2.1-debian13-fips, 4.2.1-fips
sha256:fa73062d0555895d971a092f5c7c8ffa73dfe15197360864f20fdb53e4febc1c
Manifest digest:sha256:490c4dc576fb885e969bcaa2d545895543dfdd0c48f4bb3ed65521b0ffc791ed
Size
191.66 MB
Last pushed
8 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/kafka:4.2-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/kafka:4.2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/kafka@sha256:84c63548172fffe00ee77a616525ad41c09456affb93d00c2083de8e2105033a |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/kafka@sha256:1b56b2c8c35a973c062c37c2e736adfbe8a84183b3c6461082090f5b4ee40dc3 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/kafka@sha256:0b14ef533fee11f635282fa9835cc8b77d2f06eed6af60ab5855aa17ff8a39a6 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/kafka@sha256:e934e6bcf0a399987c56315ff20f5515aec459120d392a6aa6a5f7340a26eb15 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/kafka@sha256:52f275ee1254c1807259edb926d522612afc2c53c7df31a22c0e72d0520404c9 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/kafka@sha256:3ff1333304ee50bbe41c8000ea02fd2a44ea542a7d80e40e9670c43baf077ff6 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/kafka@sha256:06f0a4df3bc00506a9509a6070a6ffd648c230085244c5180c65b9ae8bc7e940 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/kafka@sha256:0b9eadf89b5a24c0a6308e56b573ba09ec6ddd07f528bfdf6841e3022016f6ec |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/kafka@sha256:adf5c00e379221d5064e03fcd6e76df0281848e574e03decbe097b2c1ae66899 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/kafka@sha256:fe165d670dabd547f35380cdce622e4bec24d81acd1e96f7394600ac2c7b6022 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/kafka@sha256:76727eaec21d22abfb268809c5571b2d9229fcf22a724dc11d8c3408292bd7bc |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/kafka@sha256:e7547921041e811e51714174dd17eec29bc97e472b6149f062ca8e0143079423 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/kafka@sha256:d058045a51ced082417fb5a7b0b56769beeef9aae617c115783e64b2539b956d |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/kafka@sha256:f93fae168ef3dfe56ea625b1f67aab6093638af6e5e7682f1683a55268eb44cf |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/kafka@sha256:53a4a7878fb0e35c342350f4a325902eaa793d14ad195431d6516d14f3e9cf5f |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/kafka@sha256:7dd0076f0ed6791ff865b58a90cb9b6542a3dbbad890b6f7df836d522e692dae |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/kafka@sha256:be7bb217c3842c28f09a872c1a200bfbdf475386f4ccdf61cb5e04ae4bd13d31 |