Sign inSign up
Netdata

dhi.io/netdata

Netdata 2.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.11, 2.11-debian, 2.11-debian13, 2.11.1, 2.11.1-debian, 2.11.1-debian13

Index digest:

sha256:f027998102d0f7ea4066d02f1bbfe88943bcecea41872ad9b778f7301c41a85f

Manifest digest:

sha256:8bab0147281f8c662ad8b9bde5aa6f34aac4ec2b95d4422549dcbcd614636c1e

Size

169.78 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/netdata:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/netdata:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/netdata@sha256:022b65ecdd37e4398055e5a2bb8b67c21f628d2ed7b472be34270749b6519910
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/netdata@sha256:86dd2a6dc61b0a92a4eabbb76350c4041424e523ab4f36ecbc69125dfe8d8974
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/netdata@sha256:30a15982857ed6bccbd77aa15c1bffd324e85106b6d652c4dec6b31151517806
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/netdata@sha256:954b273a3dd796d8827e646ad5892e7f4e6ce6673712e64bedf001d37b0f7b39
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/netdata@sha256:d37e9dc0081bb64e1df65199790179bd33e11ade04f45428aae040629154f55f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/netdata@sha256:a9d83a8397a8c33ed4f47c714a6a443198566f0d63966a02f7ccea731a3ee959
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/netdata@sha256:29a7fb6b1253078c9e1f9956b101d7d11d909e262e67e043435e6bcd678aaa01
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/netdata@sha256:715094a83ed8c425dec34e8db8b75ac9338a277ba214d6634d7f76082d875335
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/netdata@sha256:168203c849efccf44ee6c052a19fe791342a9d475a7d836d0df40e72f11f2b85
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/netdata@sha256:694b6c0bf7f53878055539e4c895ec5052361627f63179471ecafc6e40b1c3c4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/netdata@sha256:8016481abbc4773d430f56fe54f7d841d564dc59d433ad65d4e36e00ba915bcd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/netdata@sha256:c0cee2b4bfae8dee5eb6e1fc8f1e2192ac20dab7fb7e9b9c03e3e5889877ad79
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/netdata@sha256:32dae3dea779643fce036e582034ca7cb383acd659498f46312ebc9d28baedb6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/netdata@sha256:832d09ed2295ca371f81ab76e7f482eb62ee8aa5f0eec82a496b7b13b82e7fd4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/netdata@sha256:f6cde62099ab4655c0470c4e0fee2427a771d69fad1c990d16bbd8a65df3d4de