Sign inSign up
Netdata

dhi.io/netdata

Netdata 2.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.11, 2.11-debian, 2.11-debian13, 2.11.1, 2.11.1-debian, 2.11.1-debian13

Index digest:

sha256:076a218d70cb433ed20c0577a9e792a348b8cd8548f5327844671e7c3d834b62

Manifest digest:

sha256:059d12d257afa7f23bcdf7fa626d4366ef27054f4f412f59400e2236e270f336

Size

169.83 MB

Last pushed

20 hours ago

Vulnerabilities

0
3
2
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/netdata:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/netdata:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/netdata@sha256:5e101f64c770a384bb175b74a6f1ea9a2aab085f0046c3977fb33d8c6558570e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/netdata@sha256:ac73a5e78823cb8ba2cb48f6b4b8b303267091c7cec26b6e783b8ac8476e7cad
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/netdata@sha256:a155cca5276708288747e3f085867557c8ead305aeddea392682070b16337a25
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/netdata@sha256:e0b53466f5b6a1d37a2650098926ffb6602f5db5e3f19e9eb434c74413327f54
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/netdata@sha256:8cef2d2193c224943b93d3955874cc4e494899c8b63b1dc2e77778857ef954d5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/netdata@sha256:85fcec734352b217c67f2467315e70c681ff55719505c6756f8870c6ff2fbfcb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/netdata@sha256:1a165b46577f768d524d8301fa59793eb6ca4bd8423f266512b1efd8122eb754
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/netdata@sha256:640604f4474d6c0206343089f564601e81fe5632ddb5e1768e6a4e983483bf7f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/netdata@sha256:208b334771ecad4175d9fcf08820827928ff699db005829811cf4fce74d9f54f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/netdata@sha256:c08613b5d7d1a8dcaf3e99c2a8615092a8981ceb87bb0a161da38f35d896a440
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/netdata@sha256:ee2e050dc6134fcccaa0491cc48075727ac5884b72b28a5eb29325f840dcf880
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/netdata@sha256:ca2446dd895cef5081a93d95b37da8dae472eb37df2698a7a6496f3384c9ef5d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/netdata@sha256:25577a1d8bca42c13c46ee1594978c9299b613c781f9d39353785c10a5661a31
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/netdata@sha256:a19cb05a47f15b95780f5542275f0dcad76118e7eb4f077de020d8a899fa5a07
SPDX SBOMhttps://spdx.dev/Documentdhi.io/netdata@sha256:b9fea2c894489d96708e833df481787dd8de8477b5a38ad6266a78cba57e5267