Sign inSign up
Grafana

dhi.io/grafana

Grafana 12.4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

12-debian-fips-dev, 12-debian13-fips-dev, 12-fips-dev, 12.4-debian-fips-dev, 12.4-debian13-fips-dev, 12.4-fips-dev, 12.4.10-debian-fips-dev, 12.4.10-debian13-fips-dev, 12.4.10-fips-dev

Index digest:

sha256:072a6de29a95cf67f980699e5664ea0f1e3a2bd4cdf9523f082c73a3d225d632

Manifest digest:

sha256:0be68ab56c0dd0c7e0c001d546b30d683205958931d28714ed539c64048350d0

Size

243.87 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until May 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/grafana:12-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/grafana:12-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/grafana@sha256:77e40e1a9f200f8f6c7fa9380f8cbb9453820f31546c1f722c5038d429916929
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/grafana@sha256:153f29846818d72372590e02470afe681927dbb1704344eafc0d9de312c8d5b9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/grafana@sha256:4b4bfba1a04e34cc685164262eb650669d9539f38ac58461ea2febbacbbbe7ea
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/grafana@sha256:edb062f2408367ea739700256d3fb6b59dfeeeafe2da30597b43da3cf5a0acf1
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/grafana@sha256:30a2846e88639d1d796965c038c9b4b96210b00d176c6613fb70ae45e7609da2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/grafana@sha256:8916168ba3abe68adc452d1e5a2a0585126a55c57c4eb19a29da99efc188ec42
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/grafana@sha256:a76f2ebfbfd7395f02464060bfe5c32da67bb3d569a381ce3c6a3bfcdbca886a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/grafana@sha256:c9d24d95aa483647990a5b7c4dcf810164c657e8b81f3af543caf366a3fad9d5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/grafana@sha256:4c1f291335178028a1909a9cd6515827dd653b763e6f0f60f619051911ca363f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/grafana@sha256:3c3b0401ae2e191a771b54b340ea3cf79f228a7b9c4c7960c148476ec48b69d0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/grafana@sha256:0c65317a37323d980c95cb6b006d43e2e84a0fb6abe42fcf560db897ce27a479
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/grafana@sha256:8080f09fc28f6f4ebb280702f2634ec77be1131c259276488e1c3ea4734231f5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/grafana@sha256:9568d242d1bfc622ab196518fe34dcb28c443b53c9e126fd7d98b9f36ebd32f9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/grafana@sha256:a8086179c20377add20365afb62ee9342213be71e6b97dd8aa27f4308b8b319f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/grafana@sha256:a785ed1c71bb5c0697396fd14f5925ccf04c8f0336f4c1ecdc68fed18d45e9f3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/grafana@sha256:b9e1d0b6d77cb6512a83db1eaeb409a1e90560ae5e35b3633130802893b8fbfc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/grafana@sha256:7223a76cfa5c06f5c5da9b52d5a8b05d29d6d1220facd9495ea9314fffcc8e68