Sign inSign up
Grafana

dhi.io/grafana

Grafana 12.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

12-debian-dev, 12-debian13-dev, 12-dev, 12.4-debian-dev, 12.4-debian13-dev, 12.4-dev, 12.4.11-debian-dev, 12.4.11-debian13-dev, 12.4.11-dev

Index digest:

sha256:154b924a2de895a716eb0e2663154d9e45daaf8c7b44ebdb9f027f66af8fb9c7

Manifest digest:

sha256:9e3c2ec6a3bb344eeba1cc0f294d54a1df9a36cba8f5f0ef2e7e291a049bb0bb

Size

241.74 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active until May 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/grafana:12-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/grafana:12-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/grafana@sha256:f65798c8ff3d9e1d8b08a444bb1718f5c577f0d154aa2d708d94de0d897f3bb4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/grafana@sha256:87fb88d4b292ed957a9900a140403a7e5a350c4dc9fda52b98f6e11cba7edd7f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/grafana@sha256:57141d92c83876757d51bb90f963a88c2ee6243f388c36f4a9ff37bb45668af5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/grafana@sha256:83e75ee7d2370b65a13bb49e906fce9ea681a23f453a6be165cbc9d3acff4b9d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/grafana@sha256:d60f573f14f7a9d2f73a024cf1a15f47fe03c30691418b772818811686163158
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/grafana@sha256:e028f9e17c672d7e250842ecea05dba7e1ad6b30b44588c0b94e452e5cf04cec
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/grafana@sha256:30c705b30adc6b6f1db7479574811edec6763c38c246ee622dd4b4cd5fa92c1b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/grafana@sha256:c17edc2a5e8c3506f0d69faadc32a9a1ef57c3d44d05a4b6b698150802384e54
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/grafana@sha256:bc2cdc62492c780fb573bf8557f94108f613b3a71bbdc607446720b54947f2f3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/grafana@sha256:d2e3b37146555d3aff8eedb978eac2bc71767fea601792a51a9917f72d7d3c26
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/grafana@sha256:768a9f3c6ce0b91e5cdb6f9fc06f29f2d0592d11e47f9aa8c27994856836675b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/grafana@sha256:89630cf18b8d1746b7e71f57a6a0cf46ea47121acd54c94c4f96b08aaa351a3e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/grafana@sha256:0ea68103c8a904401823a67f72c1ed045505c073b1cfb3c3bd83ecbc2a5a0062
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/grafana@sha256:79e939b00ff714a626bd2080975c1c4e47bf2289dff37408dc4b890949f4482c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/grafana@sha256:02df3267a038d04568323232b288f481f605883a11c491d8edd14c8e2efc71dd