Sign inSign up
Node Feature Discovery

dhi.io/node-feature-discovery

Node Feature Discovery 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.19-debian-dev, 0.19-debian13-dev, 0.19-dev, 0.19.0-debian-dev, 0.19.0-debian13-dev, 0.19.0-dev

Index digest:

sha256:842b5d0c650cbe108b0bdaee86f896fc3ed5c144a8e49bfbf1901ecc4b622f20

Manifest digest:

sha256:fe584fe5db61bb09c955d3f1080f2cfe48ad68c69ce21eaeb6deccb11b309d2c

Size

87.85 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node-feature-discovery:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node-feature-discovery:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node-feature-discovery@sha256:598046c59c5c7e7a2a67917e6e2d0082fd27f71c6f535f30d5df86aef4fdf7a9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node-feature-discovery@sha256:e98a6c5a6e37ef3b532c69b6e6b2e6d2a54494349aded4238a915e394718cb39
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node-feature-discovery@sha256:3838fa4ae65a75c6bc007f755027297c3543b97414f7a598de9e5c0bafb2d86f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node-feature-discovery@sha256:c3aa9cade3f5cee043e821754703b09780e7b61c3d136784f34b36388dbdc14b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node-feature-discovery@sha256:6225c105f926c60d5f0c87ce4e413ee3c852e8702244206fc2d9f66325ed46de
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node-feature-discovery@sha256:10ba0f1553d8974c4f6c0a8cd13d9564ad362fab2a510bc9190c2cf36de87b35
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node-feature-discovery@sha256:ad9b44d1a7e5dbf2bf79b712f095dab79fa3aa6d64ecf7c26b7a6cdfaa3364ec
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node-feature-discovery@sha256:46f5364a127b3e9ee587c43fa347bfccc3c7aec162e6ad87d6514ca994c99e22
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node-feature-discovery@sha256:a66435da58750f77646f7b3b38beb926c75b0f1cfdf7fb5bdd59d5c82a13f84e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node-feature-discovery@sha256:c1b3074baf299d62c1bc0938026d97e5a62b6a7f97060a4d31279eb859d4df5d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node-feature-discovery@sha256:b94e095cd8c81713533736afc3651cbf89dfb15b81e8f6f9411f7b1d8c78a867
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node-feature-discovery@sha256:f239e4992a810e8e6cc1627a67d78c260af5cea465b590bc553346a9c7cfa219
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node-feature-discovery@sha256:6ea93340ab60ea1e80049885feee074c3dbd6410750c14e71925befe73592e92
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node-feature-discovery@sha256:035dfad0ca2c52ef850ec2a9a398ae81e2d3ed12816357676f23083a161cec47
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node-feature-discovery@sha256:497a85cfdebb6847d5e76fd81de9e62b1c392f538b87628ef050eae41ac7c478