Sign inSign up
Karma

dhi.io/karma

Karma 0.x

CIS
linux/amd64
alpine 3.24
Tags:

0-alpine, 0-alpine3.24, 0.132-alpine, 0.132-alpine3.24

Index digest:

sha256:a1ebe8458299b0af46139428b8b76ed2fea9a3f82ad7082946258e7b3c36a1d4

Manifest digest:

sha256:6b74fbbbb39866466388be8688784a8dec5f09072fbbf0dffb973c9f448eb782

Size

7.34 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/karma:0-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/karma:0-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/karma@sha256:a8839c1dc818a82ad653cc0bd9e8ea50d9be67f8b682023a4a1887fd5df51793
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/karma@sha256:7caefe2eac16fb3a2ec3c09bbcaa666da92e4f44b8af170454c5f5357b37bd2c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/karma@sha256:c01120587f6b5d76dd77396bcec1003b46d2035d67573cf89d1533071d215e04
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/karma@sha256:b4cb42a21ea7f53b5ec5a681ddb6e4ab17b526c571a4d98a38562e912511dfae
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/karma@sha256:69e78069d32965630989281aebff75a9c466afbb2973511e119087123b5554ca
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/karma@sha256:04e10a0f579c35465dacafb2767c614c082051348ff52ac6157ee716629f5fa6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/karma@sha256:e947a18a05ee57396ac087d01dde7259486a71f5de1efc9670858ecbb2618cc7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/karma@sha256:50b0077691eba67d2f4caa615b032cea6f6a458e118ac8a936aff7e2bad9f162
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/karma@sha256:12227c26eddf889700aa9db944a36f6cde7855fa661a2d001adbc065870b01cd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/karma@sha256:f4320d17d58a12743f4c9647430dacb37caafbc79be5263599df185a5d975ea0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/karma@sha256:651c95ceb11ec0041b6a99dd6bdbddc5566c8e7b991cf13af02c6650851b676b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/karma@sha256:ecee6d90e2878135213b3ecb1931a43b4b3ed316bb863f0c99c29d0a06116cb2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/karma@sha256:9dde545f8dba9fe86e4445a3a71645e3db0dab017ba1f9d3a86802ed833f5699
SPDX SBOMhttps://spdx.dev/Documentdhi.io/karma@sha256:ab362918aba0a84618b387021fa4b6e7a07a79cc40170ae08885bfac776da05e