Sign inSign up
Karma

dhi.io/karma

Karma 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

0-alpine-fips-dev, 0-alpine3.24-fips-dev, 0.133-alpine-fips-dev, 0.133-alpine3.24-fips-dev

Index digest:

sha256:f6af7da3ec3f086fed3c4c8de36c1040e23a102db241537c3aa2c71dc1dd17b6

Manifest digest:

sha256:3b135f13b1df5317e558436802aa17ce0a6f2185751c346aef13f3364abb764d

Size

17.08 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/karma:0-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/karma:0-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/karma@sha256:00dafb6b3b97c1f481df962857b67eca32969949da9aedbd3b2746fc30a4b590
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/karma@sha256:838c1cf2b03ff8ae3b3b124ab1557d87a65da9c1df34fdc7b021286e3a856b8f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/karma@sha256:d988d52452c40a446ee235ced6d8afd50c2e2f997568dd56a421da4d2c7d8bd2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/karma@sha256:a2c7eddf8dbf6fa0cf18b131fbd97d139deba8ec73708eb1203df8919f3e3d68
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/karma@sha256:977fcd76e415ba2f5810c916adb804d451427513275fd209a682d8c02f09dbea
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/karma@sha256:e393b9d15931805fc4044b911a457223a5ce64f196b22575fb37c1765052833a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/karma@sha256:fe60f68d3137db84160bcaaf12c66db8b413dcea7c845de98c90c72b7d0510bd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/karma@sha256:bdd610ea1f26cca04c4e66a4ae31244e9a254d3175610cdf903adc7028326e0e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/karma@sha256:f31a5fb815eb9a85dd61447fc0279d5bde1926dd19aa614eb73269f3e5a82b27
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/karma@sha256:29cdd959d3c4c0d4ec78485477d21ba4df5fe8204e27e18204d64373f67eb02f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/karma@sha256:1da52161eae05ad9bf1597c4805dde8fc22aeade168c6c0a9b4f19b32f3d5d02
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/karma@sha256:b3db7991726e19c8503e76a287ce53bebe1957dbf1f3c12dd27cf675b8ea7798
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/karma@sha256:745ad71d02c20240e78b0c0d0e5e2f92cc9fe9ea02cb8363a09fc58aa0275878
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/karma@sha256:4019a03fda9880b2cbe15c431a5372d6be92a1aa975ee8cf9a0a8331ac464542
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/karma@sha256:50746a300ce701a1b8725a213e32bbd17cb81978fe32ef6a62b79fa572d77137
SPDX SBOMhttps://spdx.dev/Documentdhi.io/karma@sha256:79b44b050c27ec8f23a6e4ffda4c2ecb58e0fa6a99d0409db06fe10e7265e2c2