Sign inSign up
node-collector

dhi.io/node-collector

node-collector 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.3-debian-dev, 0.3-debian13-dev, 0.3-dev, 0.3.1-debian-dev, 0.3.1-debian13-dev, 0.3.1-dev

Index digest:

sha256:0d12fdba66351e66e4ad0f336d5b7c639c9c1ce09fd4c3d9851c1556fc90df41

Manifest digest:

sha256:612f2eadfba4b025198a62a951c6f289c8e51f443bdbc40284e7421e357581f2

Size

44.34 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node-collector:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node-collector:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node-collector@sha256:14a71be296610ce4b6ff3c66a0cad17c93d642d63b49586e2b48849cb43db0b7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node-collector@sha256:666e40393b4ac982b585a36bb90516d391c2585dc5515e3f58160977ecc4342a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node-collector@sha256:56c90858b056a30ee00a758eae0ef46bba3e4a7787f05179d02916962bc2c154
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node-collector@sha256:2453ba2bb83fc395f0e3af30f7f6a2a0bdc657f3d90c6b9d24f08b82c2329087
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node-collector@sha256:9253e022e7beaa027ee513b7892228d0fa1f0eca1dbf99a08cd5a956a787e4a6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node-collector@sha256:726be0766e6df6f8121f787cbf5594869f76d04c1c0d53ef3d1a76307cc23d3f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node-collector@sha256:c31c50955205d48d135f7a4b2e076f5058ae09ab08f4259332b06350fdbbfce3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node-collector@sha256:2c8e302e0cf4a8fa7f1fe7e19e5618700f27c1d6c2d832b411306f68ba9b2ce1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node-collector@sha256:1db2929f1851ab365a3cf7f1737ca123c63bcb4ffd281dec6dc7ee5a00cf3211
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node-collector@sha256:d87dc455b8dcb5e2b9043e368e9942e6591533ffdeeb46fabd92efd66d235de0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node-collector@sha256:1c7ee0ce10c30e1614b08bd7d386faae39a6b7fffa234c221ce9b266d9b04800
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node-collector@sha256:5e1899fc28ac5cc1647d806ee50ee4bafc45fc6b312743bf51bf691de64dff8f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node-collector@sha256:7ee4095a04f973cd0965d0a2fcd8f1d126f389e87a646045b89558cc6e55b394
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node-collector@sha256:45751319a86d4744f3759378d98153c0ac271bfdd94cf36eca3001004b9f3b0e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node-collector@sha256:a05cc7dfd0610c0594d004ffbcbdf47d2c17c21e144bd6110b423b1e028def3f