dhi.io/karma
0-alpine-dev, 0-alpine3.24-dev, 0.133-alpine-dev, 0.133-alpine3.24-dev
sha256:7ea978fa9dbe00662a5e7089135373ff3a5a40586f7939ea31118e3d491a4f4c
Manifest digest:sha256:bb287f5f1d80da1740a92a707b741360295cc425bcdea6a1d1988e607a2c60a9
Size
16.32 MB
Last pushed
8 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/karma:0-alpine-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/karma:0-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/karma@sha256:db12f69d933bcc5b202b917072e53dad4da11265769c4a87810e4506a6aefc40 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/karma@sha256:d6e82c3a47f26d2a1aeca3e39680fae6aea35f878a3e2ba7192e8b6e08dcedee |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/karma@sha256:200f174514718ae02d541a7204dd524c3dfcc93aafb6edf5f8f317189ffeec62 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/karma@sha256:f60acbe0c6055358065005f25c191ba33f42bc1496a61ef4816d14ffa23e3f00 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/karma@sha256:161caf0aa3dd626ccb800ad469e99255c15d80f6a5dde74c4c252e09a41bea39 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/karma@sha256:9873975c738cd9d34a4aad7be7563ef35f27df3f3f72fe374e4c2005c9a2b525 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/karma@sha256:ac1ddb9ec6ca39898c4396687a61b02bb8b06d035bb82a4d0a613895498a22c2 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/karma@sha256:cc1fb7eeca9e0dbb1c5b748e56bf80d626763cbede2697d33a0348288f606d29 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/karma@sha256:073ff2cc82a6d04a8fa7c943417264e0bda5a6524f8a6cfb2a784366c4312937 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/karma@sha256:b5f47a5efac88721cfa31f7d23e1202b35c44048b66ad698b6feb8dc5ec4ef44 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/karma@sha256:c1d1f2edeaa0931d3cb36d00f483c419a7651ff915ca102e4f03cad10d869798 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/karma@sha256:d17e40166678dae819b93f1580d2c47393a1008d03c1a9c22d558fea1f53c766 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/karma@sha256:9530bf4116a723ec3ffefb10692d3f2ec620d3fc7c1cdb5fbd4d8ad110ef8517 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/karma@sha256:0756ac75155ac2d5addc39c90317cc46ce7fc0e7eb2ec2eb653cba9c50919c02 |