dhi.io/grafana-operator
5-debian-fips-dev, 5-debian13-fips-dev, 5-fips-dev, 5.25-debian-fips-dev, 5.25-debian13-fips-dev, 5.25-fips-dev, 5.25.0-debian-fips-dev, 5.25.0-debian13-fips-dev, 5.25.0-fips-dev
sha256:68aefc47b7dd8c94c10720fc27245ec24df80e17f64c5054efd680104374be4e
Manifest digest:sha256:b04e4c03536c594d54c6e96db9b3c37fcd33550bbfc1ea9c6ac7b7b5ca6385a9
Size
54.56 MB
Last pushed
3 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/grafana-operator:5-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/grafana-operator:5-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/grafana-operator@sha256:81c38e789e547bd0ecbc0c1d04f6a2bb8990e89aa46acf8f95c1d45fd5eac8e9 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/grafana-operator@sha256:30cf3c10d9c5dabcb4e7531a9f40d42e40db2b224029e639d6762716b6955735 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/grafana-operator@sha256:533d0e6dfd9551bad90ab306160f2476d8308f1151b77c9c84f1d99c0201a90f |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/grafana-operator@sha256:e7b2786ed1d0b42ceaddc94cd87e3551fa15d1a6162ce2755c515a3ab87f8088 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/grafana-operator@sha256:8c671e505b1e5d7f600475fa2788e70210f7eb5134bb7a626724f5206b3ae801 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/grafana-operator@sha256:9079eb551482f93ec3e3955acfb96577f152642d8a1b9cf1e9ad678900af2c90 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/grafana-operator@sha256:6d90eece27e390666dfdcfe74e282e4ffa6ed0772207e3567018a4f4ec1a779e |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/grafana-operator@sha256:4a4de394d1c3d25208333001fbbb71f4bdeb95b4a12c7dd60832f11e82cfec0c |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/grafana-operator@sha256:9ab96e5a98d69282c274a2048ae9c120cb86502c24f66306ca173f412eb840c0 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/grafana-operator@sha256:84e0f7dc97a419a0927c65eb9c2ee1c85110bed1ed77f3dc765b06a75d82098f |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/grafana-operator@sha256:cd4a9280678d296cf689ab927e4d0fdfa8b66c96fc94dc4561a40ab1c7b896c2 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/grafana-operator@sha256:51d501a2dfb9f364e3f6383d0b56441b339688ba5e3fac8ecfe8156a72b948eb |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/grafana-operator@sha256:4a82101bc9ec319f348e9baed83fa296d0c250dca8db8fa358026fccfb1dba7c |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/grafana-operator@sha256:bc1e70a68c400530c8b3d5574820be5ec69ff0bbaf529ec39f24bf04c96e6cd0 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/grafana-operator@sha256:3f66025a2d96640abf1be9fa80dcf8ae6f96f481ef26b6462934f966f360dd59 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/grafana-operator@sha256:51c02c9f6c83ab9b30c979ae53712ebc7ca5f8b9cdcdb0e3b5646d279e56c64d |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/grafana-operator@sha256:aba2304fce05ed612fa26dfd3dd3f1a8b6b3fe9730f42dcc476badc5ee27a9ad |