Sign inSign up
Karma

dhi.io/karma

Karma 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.133-debian-dev, 0.133-debian13-dev, 0.133-dev

Index digest:

sha256:7f13e5d715c362ec4942f8c91aa73babd24c7fb91121f935d6ba0ca3e0a295eb

Manifest digest:

sha256:ba768b6041aa641f1f3106a301396e6813e02ef5f70f5818bcb7a0597205942b

Size

35.81 MB

Last pushed

4 days ago

Vulnerabilities

2
8
0
1
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/karma:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/karma:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/karma@sha256:675a3e09f0659c6a3b7993b81139e538b748036c7dadcd4c5e7e7e8bd8bbeaf3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/karma@sha256:fe1ba3f2ab44e5f0eae97a53cb26283410e306009d515080ec12e64a456c7cef
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/karma@sha256:c780af320e519ecd98c61e625c8e65fad7a7856eb59787b5af502ef1deb8cd62
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/karma@sha256:efdfa4c4dcc2f0cfb20bca476ad97dc7b8250e8c22f0020973dcc0a672ee617f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/karma@sha256:e97b6fd316c751c1be160e0b4877f043896bacf7d188e905d5ac55b8955ff73a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/karma@sha256:f311ebb1761e5a12cf7f9f8a4b73e2d2a2b115f1a9a55fdc6cc2ae4f4c14bec6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/karma@sha256:e77791ef7fa5347049551213bb9fe08a71aa0cd2ef33274d20156177599cd5e1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/karma@sha256:9550ff11a50e82f7b550f4dae459b3fa33b058d406d1a42ff722195bbddbb177
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/karma@sha256:ae8cebbc6f5864e561e708d8194ce6fa9d5351c38655ed9481f6db1bb3586f16
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/karma@sha256:71964635f275f14c33d2adf91e9674a1966b7322b5d55560bfe97d09eefdbdf5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/karma@sha256:d59dcce6edfc60b31132799a92d0265e599e1779f4c40e6701152ed7cc4d6459
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/karma@sha256:3e845c25fadcda08a1edd39f0bd3a62f40a18a6573c2ee158a17b2141f4a756c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/karma@sha256:f9f94b338e51ca9a144d6fbb6b8fe797a90446fb0b5f83bdd40f55ee132db17a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/karma@sha256:25fcc5a6b79de3a072ed658301360e08a575a7040a65f506356b5f538dacfdea
SPDX SBOMhttps://spdx.dev/Documentdhi.io/karma@sha256:dbab3ad248825ebc6abc11515a189b6a6a2b83e7841bd61ca30d5a49d575d840