Sign inSign up
Grafana

dhi.io/grafana

Grafana 12.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

12-debian-dev, 12-debian13-dev, 12-dev, 12.4-debian-dev, 12.4-debian13-dev, 12.4-dev, 12.4.11-debian-dev, 12.4.11-debian13-dev, 12.4.11-dev

Index digest:

sha256:9d041cdb0daa5b14871dbf80df25560935243ef8cdcff89127107bf53b432a9a

Manifest digest:

sha256:a27fb3463c351b4a1cc163006e5fc830cfcb710b9a732a29c814d3baa226bf53

Size

241.75 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until May 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/grafana:12-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/grafana:12-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/grafana@sha256:36f61d26e022fde3d2a67f6d6d4b9ec5d738e2409e261594e391f23eb77d2a27
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/grafana@sha256:f3225f29c5efa661e51cf2ea702b188549cd10565acb83cfc937b0b41c6808e8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/grafana@sha256:f08a0c845ed3e8fd659d79e33c249b3144b35e4eb192e0dc55b12382963adbb9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/grafana@sha256:b5e0b259a0c07e7a67b4448801b778187e2b64c0b8d960e7341f25762ea20d2f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/grafana@sha256:3881a3bbb596d3ac58fe1d4aff1f2e9358b00499201c910297d029439a6ec5ba
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/grafana@sha256:d0eb0b1904c4115264e38fb840614965afc83b145bd81d4b6aa1da33c78b1916
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/grafana@sha256:aa77b8804e8e82294e27c9fbac2f785f7db518b98c698a4693acd3b988bfd2ba
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/grafana@sha256:c99d490b2289c1654825f6f44257b95aef76ffee8431f725cf60f4c743e148d0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/grafana@sha256:a39e325bb63d3992830910f4b1401565a2dab5d1f90ccf3c1f66f7fb1fae584b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/grafana@sha256:1c47b865da1cbedc4b86e179b2e42e74f5479048974bbe64674a3fc4a41acdbe
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/grafana@sha256:6d41cd92423fdc2e7683ecaeb6405b87c5941f308892cd16e6c84074557cd62c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/grafana@sha256:ad0b4e7cd43c911861e4e30d120e2f1bd039af9c65ce83d087ce90b5b111234c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/grafana@sha256:d6209d5f42bb318c159d266bbd31d09a18e5600de484520c4310bd754c08ed9a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/grafana@sha256:f1f3500bb6850436b4d3625b2af3d09792ee48c8d11ee8d8728b3afa6a3d8990
SPDX SBOMhttps://spdx.dev/Documentdhi.io/grafana@sha256:50d3e76be563d9e436b535f5b595bc20ca10be0975d7a604ccf936ad5390803d