Sign inSign up
node-collector

dhi.io/node-collector

node-collector 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips-dev, 0-debian13-fips-dev, 0-fips-dev, 0.3-debian-fips-dev, 0.3-debian13-fips-dev, 0.3-fips-dev, 0.3.1-debian-fips-dev, 0.3.1-debian13-fips-dev, 0.3.1-fips-dev

Index digest:

sha256:1e8610945fe752fb9dedd9e062937f8157e2d18d1914a19e945426330ca400b5

Manifest digest:

sha256:650b57ab6f0b62cd143a52e199db7db49234812e90e0a80001eb0dd4892a5de7

Size

45.12 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node-collector:0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node-collector:0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node-collector@sha256:5169578aca99385ec11219323a1d5e843a02c59b8f79b4e39b2a824c4754880b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node-collector@sha256:09eb726798f574c907ec4e096ab7e4db38abc6936f8c585169194c2105194742
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/node-collector@sha256:b382afc7a5cac25f07c2d98cd1cde1a0e771194968c3a6258c7de78c157178f2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node-collector@sha256:819622770c46c1fd93685374c958091f100373edd5eb5f22c7b9970aad1f5cf2
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/node-collector@sha256:19f233122d370d5f6d268cf4c6f6314886e7d9063c12d1320558a97c7c583234
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node-collector@sha256:f647ce33698fc275464f0db5cf75b7962a9497a635070f29eccfc4ffb294fab8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node-collector@sha256:6bfde97b572d73ae24f61247ff12d5dc36b8b6b9495a4388881fa0415a299850
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node-collector@sha256:abee68776a9d01be00245a38887a406f5a3369abcbe061f27341d561c5e905f4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node-collector@sha256:7614b98d781da5cdde55c8768a2d6531f6fdc460a4281508703d0ffa64e55fe8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node-collector@sha256:1d0f0e7fe1966fe4080cc6ada5645101ad89273c5fd9a2ee21f7568300a3aad6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node-collector@sha256:993cd33d45d53f210c742f4f7232a6780b709a586f3f6dccd873c01e0c9a1397
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node-collector@sha256:6eec215b0cc1503da734378f71c56029e136dcbc5477fe36f86ea696e9775fbc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node-collector@sha256:0470f03218f33703d1eb80f3a4721154df7a1f39ba196f99e89c7e73df85fe4e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node-collector@sha256:d6eee0f82ff75df1786ddff7dcc31ab38e73aa0262826e686d829a53a4870f22
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node-collector@sha256:bb309176f8b036b7d47c05058e8eff875aac972fd01644eef952fe02cac4cec4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node-collector@sha256:ad5f92907fc6b9305fb8f80c6412f3fc213ad6e60776cbdb81d6ac72ccf1b4dd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node-collector@sha256:60ea094d4c2e37ee17c515112bcf16774b204729c47562a43e342bf59bd082f2