Sign inSign up
Netdata

dhi.io/netdata

Netdata 2.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.11, 2.11-debian, 2.11-debian13, 2.11.1, 2.11.1-debian, 2.11.1-debian13

Index digest:

sha256:ad729d12007ef89b700e2252e612c905bb2b1b382fa824076e78d95e37aee749

Manifest digest:

sha256:8326166cd01339ddcabe3726ec90ba2ddd13f43640d753f6b79a33cf3bd0e35e

Size

169.80 MB

Last pushed

2 days ago

Vulnerabilities

0
0
1
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/netdata:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/netdata:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/netdata@sha256:cb30e618ac1da6b3d4716ff9f66723bd645e1b0130ac5b4ddfbd9c0970cadef2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/netdata@sha256:d3f8e642d6bcdb3a6ac6fa9f12ca2b6426361e0d3dab37ced653d4b62e7e03d6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/netdata@sha256:f3af3134ab54ffbc9fbde7b7b6820241dcbefa1b1b0cebd83c61f8a3b11b048d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/netdata@sha256:78de84c5872f73bc4de749fd64a8dfbd9099cbe8037565acac32f24f6b58379c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/netdata@sha256:edb081bfcc5e5b78ca3981e426984b27668da46e4145ad32497b7571039a5892
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/netdata@sha256:c10ef5ed1c0f5664f7b3510c56ddc1d4413bf37529f747c4e517daf0d3a889f1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/netdata@sha256:6cdbb321082b95fa9830634d4f14bf021c80bbecd8021527bdb34fee9e004573
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/netdata@sha256:d9c3f9c28ddecd36c40f81352c437a143b883edcdcfbbaf14ba1d2fd10a96374
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/netdata@sha256:aae97b475c7dbbfc900b748a314a37221b2bcc53d9a1fcdccc8557c38b95e4ec
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/netdata@sha256:4b63513dc47de3c7b09f81667020a3e37f99d2483c20f0726b2b48df83a5d31b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/netdata@sha256:ce06e9ac43d1f2aff78d2d8a6edda3c58e7e4ca05950cfbda036ea8051abddcd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/netdata@sha256:3bf76f46cc6a1010d79a2ce50a867cd5019471e188bdc35eb60bd01658ea91e2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/netdata@sha256:ee462bcfde062591cefffbb6e992d4843d95adc1d499ed0ef3dfdeb39a16b5e2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/netdata@sha256:8ecc6dc6948dad347593415f786f1441e92e4fd90c43765308ba1c7cffc61c02
SPDX SBOMhttps://spdx.dev/Documentdhi.io/netdata@sha256:1fa4a4de7c48403dc4c7d3a3ccc059829079093d9911af0f24e58327aef440f0