Sign inSign up
Grafana Rollout Operator

dhi.io/grafana-rollout-operator

Grafana Rollout Operator 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.40-debian-dev, 0.40-debian13-dev, 0.40-dev, 0.40.0-debian-dev, 0.40.0-debian13-dev, 0.40.0-dev

Index digest:

sha256:3f57f5d9b4ab24ffe53e2e097cf2a6e93e7b9813487af2ce5441344f67ffa5ac

Manifest digest:

sha256:574bc5c3c4745020c9138d75a852261e2a9cdfa16eecfb37b3747e03677d8988

Size

54.12 MB

Last pushed

15 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/grafana-rollout-operator:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/grafana-rollout-operator:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/grafana-rollout-operator@sha256:80f1d684ca132140a89426605db912237e77f86d93946e0259e06022669663e8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/grafana-rollout-operator@sha256:d155ec1de2686b694da45bd75e56c8f066c26d1070897a954e26b53c3cc61ae3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/grafana-rollout-operator@sha256:ee1b744375e047fce1d60e138bad1774b8a89c81df3715b6cbada3f93de23a48
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/grafana-rollout-operator@sha256:753e7d91c0f02db17d3598932337d5790961c088c61e9770cbfcd343cd0a59d5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/grafana-rollout-operator@sha256:0daea3abe999c58152f4d3bcd6f74c3448c51ea157b22a4a39603b849b866b1b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/grafana-rollout-operator@sha256:6cd12cd8e1eb0a26ec5fb27f96dc0b574067fe514b87fb66f050f0853ccf5b00
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/grafana-rollout-operator@sha256:9bb58d88d2f87fb6cfccfd42f122efa959e03abac7f775a77bcf21bdebb8b461
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/grafana-rollout-operator@sha256:cd9907a45c5b0223045a4523988cce7fb12e520fc204cca62f6e9efb0768ecae
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/grafana-rollout-operator@sha256:5559cffeab916a2032db5b069672143f66b2f574f418cf9f8fb4e5178427a7c3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/grafana-rollout-operator@sha256:1fcc96c5e363fcf849d7cbd6e60e0fef184b42f0d04e38ba29d72bf2e06d6971
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/grafana-rollout-operator@sha256:01e63170778399f6d646f56a5745aaebbc9e332a2b7d7b6f6083b76b487fe2c9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/grafana-rollout-operator@sha256:066d1daba4a6d5a3075e15e0b9a3cfd4d06000508be0d63d42723a797ddc11a9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/grafana-rollout-operator@sha256:a1662affb19438bf02b20265a0c91ef56f5b85f9112b8cd7ec8e9dbcc030dab6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/grafana-rollout-operator@sha256:faad3bc91170bbcd5d7e550c87651d6a4c35a61cff9c4e03870b8a5e162ee89c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/grafana-rollout-operator@sha256:a951d5cfcbd8edcceb995834d4517b7ccc36ad128453bbbb6005cff50543f498