Sign inSign up
Karma

dhi.io/karma

Karma 0.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips, 0-debian13-fips, 0-fips, 0.132-debian-fips, 0.132-debian13-fips, 0.132-fips

Index digest:

sha256:f84d27a6fcb23fa528379714799da78901ee89e1944fc64231eefd01f81647ea

Manifest digest:

sha256:f70d8e7ff6d9c6b872d588a3b85472d1ec9554f2b4866a93fdd9f09aa0c07f7e

Size

15.82 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/karma:0-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/karma:0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/karma@sha256:0cf5817ea71f3d6ecd05d38c9bca0133d8bdf7af264426d58a74cab5f78636bb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/karma@sha256:c046a3fbc5bb4c05c785adb8eda6982e1bc7075d2ab6fbf63093ff57d650b8e1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/karma@sha256:7af22793e8cb2b44fb68ad91a10dd08a30c0d1aecceec4566f50692839110474
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/karma@sha256:3cc6359771a9343e23bc4bae4bfa702b249907e3894df30cb1fa85c29d2de744
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/karma@sha256:1abd1291f0bb85ea3f70407e9f91f0098cdefb64d8f5cb9a0475b9ffb789fa56
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/karma@sha256:06df6e4d55f6a784ad2951b16e9d4d5e28e11b484ef86f4775817c08259eaa0f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/karma@sha256:b09ff5be01eae1d9e68a05cd8ffec7cd10fc16c1f96d5bb74a512b9bedd5e7a1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/karma@sha256:fab3b6174b96a52da89843e381fd015de6f64f236e278a03302d46e01c9c9735
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/karma@sha256:ebbc07415421dc0d93f719e7e7736c452f2be3c5bdeae18cd32da29439ae09cc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/karma@sha256:b8028adeb29fa3b2821281278f7d53f6e8f2e22a5f72113cd093ed29c96798e0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/karma@sha256:1bdb028922773c522b31e7b027e5a0fea263892ac7edd825bba228abb574d38f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/karma@sha256:61b9c02e9a6f8e8fb63c791a8a6a9a334115cd1ce2c17f2240c490ead0ab0e21
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/karma@sha256:03236b1df5e82cacd1555bcb03f3a599dbab346433a92a52426a57903b7bffe5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/karma@sha256:c3f7c00e0921593df2c31b65f8a4f43324ec7da7bdb92499d2a12cabd6be1522
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/karma@sha256:b12ea86027f2f74bc530a066f428a069483e634b0443ef05d293b567ed3af685
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/karma@sha256:48843826569f04c75bebdf84da8e378283cef456d8e16babcd8664c051a7780d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/karma@sha256:4c00fb96296ab35b2a8dcdffa1dcb26717a626e11f46069ce21ad5a4d2da1a9c