Sign inSign up
node-collector

dhi.io/node-collector

node-collector 0.x

CIS
linux/amd64
debian 13
Tags:

0, 0-debian, 0-debian13, 0.3, 0.3-debian, 0.3-debian13, 0.3.1, 0.3.1-debian, 0.3.1-debian13

Index digest:

sha256:0e2d2d41192d880fc251425614df40018c37d9d849f48d688e4986333a8e2987

Manifest digest:

sha256:e0407b66cd341c34b88d0820819b016b18e399747397f06cb020aa9947a8413e

Size

21.49 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node-collector:0

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node-collector:0 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node-collector@sha256:019284a58ca7592b10054cd3b136c1445f4300d586ed18e415bfdcacb5080059
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node-collector@sha256:86da617cc655d779aa1ea900856ea0fb333760388685381fc6dbc2d5cac3389b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node-collector@sha256:1afb1e604dc99a4af9c12f9db5e60799c41c895f7c316091916707fa58b7b2d6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node-collector@sha256:fd4c3d3b2e7c5b6541f236d3a44ca7590fe84acd009e6e44c4bff9e0eedaa0e4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node-collector@sha256:4ac1d7294107099b982c4b34c324abf18933e2161a3a2fdde4f8fccbb6467119
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node-collector@sha256:920dad56eecc6fc7f1aa1dc327dd2b684da7e5e54978f0bad5901f89dfc9e2c9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node-collector@sha256:27248537d0af6911ae82c62adbd8476aa5434f69b056fbbd334f58c9e9908e9d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node-collector@sha256:0684c3c0d2a090884ca48bdf1cacd5d3df7062efcb738f3c604b83d32ae213a3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node-collector@sha256:fa6b518d312309a04badbb7e06285ae33c7a2fec840b6e43411c11ec9559f065
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node-collector@sha256:c01c0320ec1ac967db1270e124bdc02b2d72b18c836b922082cd2b7cde95d1b5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node-collector@sha256:95aa577448825880db6d3540b85487b1ebb25975644a5c91df0261ebfe5aaa3f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node-collector@sha256:a81d2a7a8a5b322eb9f81c535e4712a534d391b7e331db17bc3fd911c573ad93
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node-collector@sha256:f751650ac8023744e24e65af29367b8c519bed3b6f7773c215b667cd156e49c9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node-collector@sha256:9846e4e90be48b1806dfb507b86db611b37eceefad39adc2cac960abbc04bb7f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node-collector@sha256:c1f8ec3a0d517a3ba9a5aaf9e75841b4c36658ab111b23dc16bc2bbc7e33f2df