dhi.io/karma
0-debian-fips, 0-debian13-fips, 0-fips, 0.132-debian-fips, 0.132-debian13-fips, 0.132-fips
sha256:f84d27a6fcb23fa528379714799da78901ee89e1944fc64231eefd01f81647ea
Manifest digest:sha256:f70d8e7ff6d9c6b872d588a3b85472d1ec9554f2b4866a93fdd9f09aa0c07f7e
Size
15.82 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/karma:0-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/karma:0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/karma@sha256:0cf5817ea71f3d6ecd05d38c9bca0133d8bdf7af264426d58a74cab5f78636bb |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/karma@sha256:c046a3fbc5bb4c05c785adb8eda6982e1bc7075d2ab6fbf63093ff57d650b8e1 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/karma@sha256:7af22793e8cb2b44fb68ad91a10dd08a30c0d1aecceec4566f50692839110474 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/karma@sha256:3cc6359771a9343e23bc4bae4bfa702b249907e3894df30cb1fa85c29d2de744 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/karma@sha256:1abd1291f0bb85ea3f70407e9f91f0098cdefb64d8f5cb9a0475b9ffb789fa56 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/karma@sha256:06df6e4d55f6a784ad2951b16e9d4d5e28e11b484ef86f4775817c08259eaa0f |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/karma@sha256:b09ff5be01eae1d9e68a05cd8ffec7cd10fc16c1f96d5bb74a512b9bedd5e7a1 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/karma@sha256:fab3b6174b96a52da89843e381fd015de6f64f236e278a03302d46e01c9c9735 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/karma@sha256:ebbc07415421dc0d93f719e7e7736c452f2be3c5bdeae18cd32da29439ae09cc |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/karma@sha256:b8028adeb29fa3b2821281278f7d53f6e8f2e22a5f72113cd093ed29c96798e0 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/karma@sha256:1bdb028922773c522b31e7b027e5a0fea263892ac7edd825bba228abb574d38f |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/karma@sha256:61b9c02e9a6f8e8fb63c791a8a6a9a334115cd1ce2c17f2240c490ead0ab0e21 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/karma@sha256:03236b1df5e82cacd1555bcb03f3a599dbab346433a92a52426a57903b7bffe5 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/karma@sha256:c3f7c00e0921593df2c31b65f8a4f43324ec7da7bdb92499d2a12cabd6be1522 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/karma@sha256:b12ea86027f2f74bc530a066f428a069483e634b0443ef05d293b567ed3af685 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/karma@sha256:48843826569f04c75bebdf84da8e378283cef456d8e16babcd8664c051a7780d |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/karma@sha256:4c00fb96296ab35b2a8dcdffa1dcb26717a626e11f46069ce21ad5a4d2da1a9c |