Sign inSign up
Prometheus Node Exporter

dhi.io/node-exporter

node-exporter 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1-alpine3.23-fips-dev, 1.12-alpine3.23-fips-dev, 1.12.1-alpine3.23-fips-dev

Index digest:

sha256:e9546588c86fd1855711847b60a84aa16cde1f0cba18bd5c94072bbc4ea83c7f

Manifest digest:

sha256:c5885a0cfca6b3619bed51449cf8e31a81dba52bcfcbdac0488b58ffb7f53100

Size

15.62 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node-exporter:1-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node-exporter:1-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node-exporter@sha256:f3f00946b222bcf143653df1a8ecb0bf17be90b10de3934a84e432de8b0d2acb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node-exporter@sha256:01e7b72e00539635c9625a8a4c727a3781c86c5f9035e4c7954691f6d7ccbd9c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/node-exporter@sha256:b0f2ec630c2e8c54427c4321a19611473216a0f5d8bede07cbbff871fec71e22
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node-exporter@sha256:7b223a9dc5760e905bcabcd41713a8630ba25322832c39dbd5ae26ecdf7187f5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/node-exporter@sha256:20a565862b31608bfdbe6e74e1eb18bb45a0d4c854f89175efbc4c644fa5a4cd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node-exporter@sha256:65837781d06c02cb4e81b68cf5ef75834f837a13ba61820e3ade9b729dbf3501
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node-exporter@sha256:a9ed70a016051a9ec88cc84b724ce661ef58f2983c77562f77d39c27c6f818e8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node-exporter@sha256:cab7424c8ceb2b69894d4892907a75d49d0087a272873662076c888570c4f56c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node-exporter@sha256:849ba5d22f8f800af1132637e08db50e5a46ee69074146d1d801b134f68364ae
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node-exporter@sha256:e83c360092e2e195d5b933ae6e142c093fbaa1c48ef35babf1edf8cc8fc20ab8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node-exporter@sha256:3bbc3b66dbd1ac9f4f012b95a90baf5fb48cfb8745f291e4d75252a3603834f4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node-exporter@sha256:1cbb5f8f02992b72a469d45921f1695b53f285e85ba1c5d04c1094e4572c8f89
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node-exporter@sha256:7b5899961bc75607ac7d69981cd213fa36e9a3811ec2fe7f1baf9f0e976f67b5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node-exporter@sha256:c198b772f275d3d4c0221972829445c7983f062c69abd5578ffdb99b3c92a680
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node-exporter@sha256:07787e1e97c44f912533445c804b6032b6fef12954651a195508cd525ee0ec10
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node-exporter@sha256:2fbf5f685adfabaf33b616e03dfddfcff165a8948a28a8788ed1592862b9d4f4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node-exporter@sha256:046ad16c0a6f5df9c8466fdb719743282e5e24ecd0c4b3cf33ed15ad29695eae