dhi.io/karma
0-debian-dev, 0-debian13-dev, 0-dev, 0.132-debian-dev, 0.132-debian13-dev, 0.132-dev
sha256:8580c224eb44ee74166dab51fa11f4cc27ce9435665ff50746c951b90b981434
Manifest digest:sha256:107355bc4064b206d8f64990c4726423b82804872844174de2f1b4b2ea4907c6
Size
35.46 MB
Last pushed
9 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/karma:0-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/karma:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/karma@sha256:f163097d99143dd65e1211781926bbfb0c280ddacb021a7147a050f34b0a2bcf |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/karma@sha256:6e3747f5c7d9b40f9c3ce9a7971d1267d774a4c279df0f88d71499f1a1209dcb |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/karma@sha256:7973eff128d6b9cc6a1a332a90a90e5c4bde6280ab414f1b4975ee0f3a487ce0 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/karma@sha256:572360abbbdd2626cbe8f0863baadd2d84d811fb1d066b4bda90e389d96d88ce |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/karma@sha256:304c6196015d13ff9f9152fd0b34e9b59716bc38728105910f9d435fc116bbbe |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/karma@sha256:42099a8d1e49ca466fe8d499f7c3b1455b0c649881daa6eda330931522916673 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/karma@sha256:0fc7e995b480fded3d48218add605aace773ae45042da93f28b1203dab2839bb |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/karma@sha256:402f38637c35eb4a7ec6ed0f2b472b4617de1bc8ee27ce898582936e5777f567 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/karma@sha256:80e5eaf17da68cf876363d749bbc84caf6fa4518a4133795b8fa2a8979572b7e |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/karma@sha256:ff30b4eff6d5e7ad7700e4108bc3d147f2e66bded0008fcc83f637bdfcfe2396 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/karma@sha256:bc69ee43f1a30756f72edef209fc9a2f76f85f4dbbb976e96fab40a6bedbbe67 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/karma@sha256:f747a4f96e637063b8c54b303cbc6b6c04629f2a280b71a63f706fbd0d3ade14 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/karma@sha256:2a67cd7481e79711531cfa8be2f55f54722e08f25e4ccb818ae850caaf3d3d8f |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/karma@sha256:3fa77a5d02dafdcb9838618c842e90c553cd4efb0081699bdc6343ecec84f576 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/karma@sha256:fd830bbca2845b76c7f4d2c47e87c2219c188c3dc770fe0761bbc055360a2a6e |