Sign inSign up
Netdata

dhi.io/netdata

Netdata 2.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.12, 2.12-debian, 2.12-debian13, 2.12.0, 2.12.0-debian, 2.12.0-debian13

Index digest:

sha256:56207b9e83119ffc921b3a50302365aab163d99690e2a934c04f516a581442e3

Manifest digest:

sha256:7f9df4ed53dc9ca20444eb5247bcd305c3f124e39a4c8d6d9156f2ba8ba11853

Size

115.67 MB

Last pushed

14 hours ago

Vulnerabilities

0
2
2
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/netdata:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/netdata:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/netdata@sha256:16843f5cda10364e1ec7af8d56810ae697074d398fc4b33ee45a81d2e7804cb6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/netdata@sha256:0035946c93e773661bc8688d211917551f5c4738630ab294d1799c3fedfcdf31
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/netdata@sha256:b84f2d45a716d6f367231563d09ef6f6b0e19dfb3e0fc8a8aac98354fbf3cc13
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/netdata@sha256:c12f5fa6e8e75067e8525414c85034bfa2a3593cd60c1176f2dca96ad5e3a893
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/netdata@sha256:b2c45a45445235aa2acda164b2626f54664ba8231ceb650b1d6dc5b47e6efe1d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/netdata@sha256:8e199db467d0d334c5d376e1fcd5c4e41a14cf30ee582423bb6eb6934b79134c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/netdata@sha256:f2b4a4c3889f349f226dfde56bf3410640f911528218edf2bda66524faa03689
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/netdata@sha256:51be0eeb53eac65008a48d20cacc405c04a25eff2d3498e65d2a85a7fa8dc058
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/netdata@sha256:35e66f8776bf0f977b8721e3c951699836fd70d0b9dd0c62c13b00112229810a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/netdata@sha256:d1cf6d9664c19561574fd36ff91b6108232c24781ea43f7e7be291ba69be1eb0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/netdata@sha256:755b7645a0ddd08cd9c46a108be07ae04de593e544fdbbf423d83b983badfea5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/netdata@sha256:8fa4a1cd9b08f9cf96be35572bade8083faa294d713172339eb6a73fb1458830
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/netdata@sha256:cebcfe3d2bff354b1061841709c0b26e8e48ec2c6d322d207d12fd171d1ae2d6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/netdata@sha256:1c1f91490411cab42aa5d3c49098596b7790bf9ab4e59cf3b2dd9519ef3fd990
SPDX SBOMhttps://spdx.dev/Documentdhi.io/netdata@sha256:845a7c1a8d69f539d0f547969bb06f743bc2492c29f3a75fc25e94385db3d992