Sign inSign up
Grafana

dhi.io/grafana

Grafana 13.2.x

CIS
linux/amd64
debian 13
Tags:

13, 13-debian, 13-debian13, 13.2, 13.2-debian, 13.2-debian13, 13.2.2, 13.2.2-debian, 13.2.2-debian13

Index digest:

sha256:686af1d55ed4d98447691028fd46bdd40833fd053df0144980fabca05a8f3382

Manifest digest:

sha256:7ffc0551ec95e0890d23168cf601b399cc35f983f053529e3733688f43c4734a

Size

255.98 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until May 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/grafana:13

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/grafana:13 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/grafana@sha256:e2aabab80af545b07793746a2a05ea687f91690d627585e894a130d187a1c179
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/grafana@sha256:b2372353ffd3b00062ab257f0b312260223272dc343c79d13f63f73236086897
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/grafana@sha256:425428d382c9a2e4ace0b10c6a505ffe23627b0a72ca3b4d7de23504e89221a2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/grafana@sha256:b82ccdba7bc26d636169f2874b0f626027095f0759c3ff0ff62825ec104c283b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/grafana@sha256:06b163865fac2a346afdb480a771780955fab9e08789cc7b2301d71fb0d55b64
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/grafana@sha256:98073ecfd234638986bf34bd2a8ea6b1d297adadcff0a178542263b507f7cf58
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/grafana@sha256:cd85184c19081e1df9544b7b3b9d26518caff1ad190a03b39764013dcc65ea60
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/grafana@sha256:de7370a264680d8d4c1eed9b02ef2c2e56b9fdcbe9b851eb4f0c91d4c5ae8d44
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/grafana@sha256:35d64b75f957ccebce2fcb4506a66998fb9941ea0af5878e63c8a67d955c27aa
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/grafana@sha256:f586659456f3b24117cab0f3b25ca4fc80c89e12818a571a20046cba8e342b72
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/grafana@sha256:1b53a8f1ad1a20b37c5e96d7a5f110a5764e318c1d20f802e44b673f7474c452
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/grafana@sha256:b80583460ef9695fb45f3941f159f10719ecbb9f36e9ab839ff43d45a4617b13
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/grafana@sha256:54c63d38c45b51bd58c1a4e6b08180bc6dad6a1e702fd8b0e72e578b4db5ef75
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/grafana@sha256:ec214fc3ab0c86e7d80327cf9b1d4dd346c32f86dab3c849cce7bee19b6a5df9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/grafana@sha256:6e5efa60080131113c227a41573af870313b12a99218b1801b4ce1b3b01329e6