Sign inSign up
Netdata

dhi.io/netdata

Netdata 2.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.11, 2.11-debian, 2.11-debian13, 2.11.1, 2.11.1-debian, 2.11.1-debian13

Index digest:

sha256:932e96883493209ad38a93336fed946dcdb960aa5278b728344edbd2e2dc0d1d

Manifest digest:

sha256:b0115ad59a9cb1592b1a951fbfdb89c455393d3a95e1fce109842ed8d7682797

Size

169.80 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
2
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/netdata:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/netdata:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/netdata@sha256:829c4ae3dbe50d7e59368484fece8f533c40d112d25718745a7ac361d1627919
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/netdata@sha256:c8e23d70206117400e901e45a8d16b071e8c055e09ff16d5d28af3766f9539f7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/netdata@sha256:3394df06e85aa58c71f51edbf98a55edf6b5a30c719673bc4a7cde9a0c1973dc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/netdata@sha256:de4c875a582311708dc67b7bd8d631875d02ba8d52ea05d16bf050d35ed13ab7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/netdata@sha256:f2a1733b514fed26946160762cb5d468517929751a93822a278076eeb28c84a5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/netdata@sha256:7d58e41204183881f6b5b896cb9d2d9f5b1dbdc85cf54fdfcac6e63c835324af
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/netdata@sha256:2b2bd46b9df487b8a75abc71cc1e7320a0964ec42f1167fba21aa7b3b80fb01d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/netdata@sha256:1a9d6c1bfaed0baf349650eaa5e4754d5f5bb48d708d1803ed4e07dd0e9cb0c6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/netdata@sha256:1645286c89f5c4ed53f902b128c69a9fa40488c121ed3fcd73fff1c2af4d9402
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/netdata@sha256:1c0c9c12a7411f6e6355c74d65cb28afd9699c3eb2937df1bb743583988bba98
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/netdata@sha256:74a79bcc94493255fdfeff2df2ce7c6a426b590a01b2a78d35e3d506973a5da7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/netdata@sha256:6a9570a48101328ade5efea31f6b4ec8bdd17605979b2fadd072376f7d04b173
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/netdata@sha256:9b62fa46d4dc7ca6b74c74f1a36b749e982f59aad6b4bbbc6a8c1499a7f1c43f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/netdata@sha256:063c64d954535c2b8c7c78ead442f688780bc1101a89f801c0a3f741b4f22f35
SPDX SBOMhttps://spdx.dev/Documentdhi.io/netdata@sha256:0cc0c1343c2bf1eec5dbd540b75f72927151e9787a5ed14977427f78c4016649