Sign inSign up
Grafana

dhi.io/grafana

Grafana 13.2.x (dev)

CIS
linux/amd64
debian 13
Tags:

13-debian-dev, 13-debian13-dev, 13-dev, 13.2-debian-dev, 13.2-debian13-dev, 13.2-dev, 13.2.2-debian-dev, 13.2.2-debian13-dev, 13.2.2-dev

Index digest:

sha256:94db27c39447d6e1265b1901642bc7869baf27afb8ce8b0240cc5851c5b909ae

Manifest digest:

sha256:bdd8cd73992d75af39c0929a00d3c2afd79c6cd6e57912d17ada5b32a2df0124

Size

272.55 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until May 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/grafana:13-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/grafana:13-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/grafana@sha256:c600764c1e26383cc2f16531293bda21823081d31064a59934367f102e2a7f9f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/grafana@sha256:5f7a1812ed44504ce93030f2163df8a1156446bbd326ae6bab80de1175f1b91a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/grafana@sha256:05c41f74c87e60e34ae417768f64ca19178912cc2db61857dda71f81386e8b1f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/grafana@sha256:259ed3dce3ed758fe922c829089549bf0a0e9461c2dc8f69b5fc6816611ee6fc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/grafana@sha256:73216276069fb2dc1b548e5a04fa421bd71858318356b13d7664f434eb812cd1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/grafana@sha256:3bed2b734cf992f29de2214881aecd30f550a1648e8be93efb58541a0dc927ad
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/grafana@sha256:8f312da95bc41f5d942356a04feb319115c71134e02bde4e50a1f91ebd09ac82
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/grafana@sha256:bd740b21b0a7944353b0342439144b67e818c37ea42bd7f308c5b0e93a8527cb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/grafana@sha256:27bc9492ae4c1e76c30004e549258917d61b6b526828436fcd5e4f64e098e6f0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/grafana@sha256:2e9aad305cf7b73f5654190b4d5420fbe1e4dffb501612245f96d2129183ea82
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/grafana@sha256:5612c7f14f23129f9629576031ed39957f9adbbb5763424eaa47733b98695789
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/grafana@sha256:11738e301c4c050c8bbe384c2afb1d2133034367e1d18eea65457afda80f188f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/grafana@sha256:6cb53f6e8ce33e110c0af9daca62951480231aeb98dd86cc9ccd2d82afb1a9e3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/grafana@sha256:198ac42c0c6949a0935b8f4fb22c5295da5a4564b41eac5d4c3ea235018b7992
SPDX SBOMhttps://spdx.dev/Documentdhi.io/grafana@sha256:cfb9ab383df2a2b836497a498e5363d9fbb63d2ae475656b5a92cf1c755863f8