Sign inSign up
node-collector

dhi.io/node-collector

node-collector 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.3-debian-dev, 0.3-debian13-dev, 0.3-dev, 0.3.1-debian-dev, 0.3.1-debian13-dev, 0.3.1-dev

Index digest:

sha256:f6426a3ae5778b49eea011d7b47c6520ab77d2a0244f058233b03da5671669e9

Manifest digest:

sha256:802f28e1c8d9b189a05cb92ea7a667c230a6267ab497f57f8a341b8c3c870503

Size

44.33 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node-collector:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node-collector:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node-collector@sha256:6d5f1385569439aeee0067560d07e4bc7ec777261d527ac696b4a165f8d39614
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node-collector@sha256:4d64e204a72ea734ab448208eb96cc8f8c162b7c851588cbe2bd055a3e9619d9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node-collector@sha256:a342fceb24d5912ec99815ebde372ff4f0608dd63c31b7c67e5432d6accb896b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node-collector@sha256:fc552958be44f0bc2fd7f0d8f331507763969b3876ee5654fb856737893ce3cc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node-collector@sha256:0222f5137407a79281a0f2933d3f76543e3ee2d219d3ea48297f0b531d5dc2ef
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node-collector@sha256:ad51a23ad170ba3ce2d352827062e121f634be00de4cfe549d072a734360f0c4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node-collector@sha256:4cb7d39fec19953422e74aa1ecb544c520666f5bcfa8b37fc65eb51c3f720af8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node-collector@sha256:3631305160c5b96749fb78beb793c52b52108bb20abbd850a329432677ec9944
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node-collector@sha256:44781b8e5767363bd289e6c90e9daf80ba706e208a086fdd24458cfe83edf6de
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node-collector@sha256:267bdf11209b67070ea8f9379e9b937c4b779aad714936112b88507aab732a94
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node-collector@sha256:aa3738048cd3a23505b32c8032df50164475ab1857f60a84e49008a9d20343af
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node-collector@sha256:5f6f23fdfb9ad6e11acd3b8ac8c1c0c9933022c8dcdc7a37d3a9df649b2c523f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node-collector@sha256:c65042a0eee708fe25a5ca92ab552515f2a8f3c5af1c101a75bc9b0d0cb1a36e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node-collector@sha256:1810b934bf20f24dcee731f8985ac955fc1105778473b95901a6dfed689c0474
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node-collector@sha256:833f6f6dac82d58078e5ab93ded4d4b4dcf4e32d4cd228d36e1630808cd72403