Sign inSign up
Grafana

dhi.io/grafana

Grafana 13.0.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

13.0-debian-fips, 13.0-debian13-fips, 13.0-fips, 13.0.9-debian-fips, 13.0.9-debian13-fips, 13.0.9-fips

Index digest:

sha256:636a0ff8507860e1358d1f81ded45f1cc54e0dc75fca915d987e3c5e29b30bfb

Manifest digest:

sha256:ad29d830d7de07cc79c05f8ed877aeb22dc4ad23f5a77365906ff98c58104525

Size

256.92 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/grafana:13.0-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/grafana:13.0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/grafana@sha256:d1923605e1a10b692998793a2c5bb49ae997f35930c296b1dd0d54b34419043d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/grafana@sha256:4ec4cab511fe288ced80f91c8d8bb9bc457e8d6fabbb339c9d55ae1e201ebf24
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/grafana@sha256:f3f7fd395e3e5ce58a98e266616d52fcaa3194859abb9b3fe6497db2154b60cf
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/grafana@sha256:fd09a53474a898310fc595578cd368202c528b52605323ac2b04a457df88ccd9
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/grafana@sha256:b54abea6363d4780ff6935048e27b25eb9bf707bee4a439634e41d8e06a26482
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/grafana@sha256:b59e16bc0296b17a30e358c7ae68d5b34059fcf5daa6f7aebabb480db9b64114
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/grafana@sha256:4dd23a133f0c8a6b1590d41e4da4a587d3c6b95d976c24d01a72a38e1b796286
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/grafana@sha256:5da9adc93f03707e683b6ff36469e60faaa4ae3ad274d19f95e93c3038f5475e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/grafana@sha256:eedd04835c2e974a8ae02edf20ddbcfa23be888c6dbac3b72ece7d7741f6eb25
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/grafana@sha256:7c56a9da86011412dbcf9c47e875bda683a93b05a2a87263f442ba3f459e8ed1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/grafana@sha256:6a5c38118f934e6283d14e641d8e978183c9377a8612dade7cbf8f66a739fbe2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/grafana@sha256:de26ccfb17351b2f2e01b1172fc5f4eefc80928545da70e51fb8cf34f80b0b96
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/grafana@sha256:2aa21ff95954523c1803ded5d86eafae307b5d66a437b621d8d4c008ea1b4625
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/grafana@sha256:4933d9548bee8b5c8576a6e66197481ba35bacb454f524d1a4884e53632f3dae
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/grafana@sha256:f98c2b48c80e94befbf5e4c0c719bcb8967922b549244988cbd447722b6d1d69
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/grafana@sha256:d771a6a89236c348f0c00de4f12b0a1af829ef1a87d2187dd94ce31de1e22808
SPDX SBOMhttps://spdx.dev/Documentdhi.io/grafana@sha256:2b8e491c290de2772b4cebe30eeb9ce6449c96037d6530e5f9b0e2e9b6b28f49