Sign inSign up
Grafana

dhi.io/grafana

Grafana 13.2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

13-debian-fips-dev, 13-debian13-fips-dev, 13-fips-dev, 13.2-debian-fips-dev, 13.2-debian13-fips-dev, 13.2-fips-dev, 13.2.2-debian-fips-dev, 13.2.2-debian13-fips-dev, 13.2.2-fips-dev

Index digest:

sha256:ac98a32513d72974eefcacb156bfc15e79bc70fa0e0c2d0fc7571f331ba231d8

Manifest digest:

sha256:5532387a6912bac712bfb291c2d90c5f996a34feb6c1b8600de4f1141d8cea4a

Size

275.10 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until May 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/grafana:13-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/grafana:13-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/grafana@sha256:be54533812c9a4e4eb80d0bf0b29cd5cfb96bb7991e851d7301c32dc362ed702
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/grafana@sha256:daa5a87df0842152d3c756e96c36d3b9b2de7994c3d15d9b97fd0f1a6145d346
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/grafana@sha256:7eca368e7aada5244479bc1ef84382f5a09fdf1d677f2ed819920d5260190c7c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/grafana@sha256:0dfe8edee88687325b71eb7edc7389ec2d357189084facab04b5f904278b8f65
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/grafana@sha256:46a95d12db47c872bd7a003276c8626ba89e406b3dcbd62de2761defc1a7e33c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/grafana@sha256:4a64a5b37002266b632f11fdf6c6f5a5f6380b7cd4c804794b26f7569b75361d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/grafana@sha256:6602700ee90f0a580f44241a0b8823345e3888c2765608bc450b5db9c99d083a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/grafana@sha256:e21c9e55ed0862dd538d6c821ac8bc737732a109eb36a21b334984d2080f42ca
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/grafana@sha256:6090234b72e745463757abf774d1d138a1e937283296c059bdcad8862bac00b3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/grafana@sha256:0eeec75c40c490f55ae3864cbed2e2f1286ea58e23e7a09a340568a8d5e8fba0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/grafana@sha256:0710cda40c40b7aa77bfa171c5b26303631db1fffc8be3844f46bb0d4817def6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/grafana@sha256:938b87fac0f21de7c51fd1b37400d90beb8825791fea862cdcf3c7d860b482f8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/grafana@sha256:263e2a113332104e5d8f54d4af34cb4a4283a913877febe4923b36675e1c2abc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/grafana@sha256:defae0fe4412f3efec4e2b2fe10b75e9884c67fb8ba4e0c6eba86d2e18403122
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/grafana@sha256:e057e5c5848327415edb9a817f874ef643cdd307ca7d607f204d8d1249cb5866
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/grafana@sha256:04d57b0500ffcfe7f0e669b79a262e617d11af8565086c0e1c5061c2ed3e35e0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/grafana@sha256:04fb2da1c40a8a2f8bba821516801e6270b0fe52bf2df80917eb9c3c52687b2a