dhi.io/grafana-operator
5-debian-dev, 5-debian13-dev, 5-dev, 5.25-debian-dev, 5.25-debian13-dev, 5.25-dev, 5.25.0-debian-dev, 5.25.0-debian13-dev, 5.25.0-dev
sha256:5db783e3073a35b9561227a6de054f4cf2fc09bc7c7103de64c878cdd3a28698
Manifest digest:sha256:5a574e0e4523b7ab9528ea06675222caf6c4482a8cc3525799600dfa7802aab5
Size
53.81 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/grafana-operator:5-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/grafana-operator:5-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/grafana-operator@sha256:e5e6374866f236e75fbc5b308cdb2970538fdece2f873906f18c8300cf450d83 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/grafana-operator@sha256:df31f991b984cb8ff5edc54a77920d70c20a42efef70f1bd551f9c9d285b9cf7 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/grafana-operator@sha256:5f3a3ebeec60a5f430442a7e04ff551c2099e1d05113c996e7c66e3d4d3ce748 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/grafana-operator@sha256:c7354a007084bdd4c16361f282bddb18081c8dcd12b443797e41916db00a78d6 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/grafana-operator@sha256:2366b91826932f885fc3dfe314ba5b1bdb475bee677aa616f0b867d49a59db19 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/grafana-operator@sha256:17984deb135d8f932e10a12220d9b8cf27129fda147e4762bf31b93b5561fade |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/grafana-operator@sha256:59cdf6d002c2878ae22eba411ea0b07ae1041a8d37fa14d638e8e18a8f2f4e36 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/grafana-operator@sha256:c1dafb6d5fd625f1612958eac95c1b19b46ce246659b15cf82fb6d977820a92f |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/grafana-operator@sha256:8414ebb7dddfb24c3f0e46e73235eb57d3a51e7466e4c22e9351bcef95de7e90 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/grafana-operator@sha256:b4f36e370a610e3fd3646c20f7923309742fe97ff9e52b89f1e506e728fc4735 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/grafana-operator@sha256:185f72fa1c5f93d7b112d9a52c231a38161b185cb688a15c89b28ed4be25c0d8 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/grafana-operator@sha256:b9ab57105f55b15884e459b444586d9aa17d216297836147260a6c78b46c62d1 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/grafana-operator@sha256:31d3629ca59a4044f2fa46ec3c8df13d9dd6bb0c67351a0d5eb8aa2b5143f452 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/grafana-operator@sha256:383a0828faee17abe2a98dcb4891a14dfd306a7afe6f4fa2dd2eb33cf5abf83c |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/grafana-operator@sha256:2addcecc617a2d7d3fe873204711d0d6063e15ec468ac44fa5bcc4475af0fbb0 |