Sign inSign up
Kafka

dhi.io/kafka

Apache Kafka 4.1.x (dev)

CIS
linux/amd64
debian 13
Tags:

4.1-debian-dev, 4.1-debian13-dev, 4.1-dev, 4.1.2-debian-dev, 4.1.2-debian13-dev, 4.1.2-dev

Index digest:

sha256:eb6eeec60b5c06a12f1aadfa9e47e88a46aac115f3d9fa7de88f3962e4ed1283

Manifest digest:

sha256:fb6df191dbfdbabb49c1258ef14e37679823286c8affa6fc09c451f17a8ce0d5

Size

195.08 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kafka:4.1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kafka:4.1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kafka@sha256:c50fddd22b91f5a74727d3ec8e2f8b4f85ce7dd3042cbb2de23e06e95885571c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kafka@sha256:2d0d8f7542ce260b54d6853d5fdc4cce185d88adb5b02721e924f08e50029020
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kafka@sha256:8de4e687c4260da38a748113d42f3639f648fb61e1250830cb169bb182ef54ec
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kafka@sha256:add748a28e5b45cc23c5dd253f5085c7eeb04f0cab850cb7e4a5e5c940a6beb2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kafka@sha256:b6dad1ae34007228323d8f396be1792e1e434c243b9f1934029af53313380455
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kafka@sha256:16a53d34e25ee2dc66ca406ba18987f191b51e15fe3fc2ed139264255a9b33f8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kafka@sha256:3d96a5ab3b1d171c544a8f32d124fb675839a1cede2b6d5d9cb7ec89d13d0f34
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kafka@sha256:87f778e15553fa52da098563d77e9b4145c2e7e215f3112cf36e2a4fb60a7bde
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kafka@sha256:7acc329ee251fe25ee96035ccbc98b801b9bf3f7ef9f099d01c2c273efe2c77e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kafka@sha256:9891947570d82fc57f99618f96076b6696aee9a4f31d3742faf240a313954493
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kafka@sha256:d8694e208c088a8c1c851d719d69fcec5c69f42169ddb964100cb21e918b6b30
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kafka@sha256:a35d944c4736f48c487e4df355a2115e6dbfd2aa8523ddd1122d78090a98e3ae
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kafka@sha256:f618767a9b90fd210a60c454203aec40e5136c649e95fa770b007cc95df9b6a8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kafka@sha256:71227861d19d744ffd938f44d6f92624badf773f7df0e7faf9d6676450167521
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kafka@sha256:0119eb882b426e0bac5b22d2a728955c35c53ffc80478e6dfdf0147c78c11fa4