Sign inSign up
Grafana

dhi.io/grafana

Grafana 12.4.x

CIS
linux/amd64
debian 13
Tags:

12, 12-debian, 12-debian13, 12.4, 12.4-debian, 12.4-debian13, 12.4.11, 12.4.11-debian, 12.4.11-debian13

Index digest:

sha256:2a5863c455511c1d1aee97d7e290992eade22a025909c2b1763c4412f6dc7b3b

Manifest digest:

sha256:0eaac8274d62636d3a721ffee4a31d9e6828399a5cb3c62f2916e9e96db0bc8a

Size

224.68 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
1
1
0

Support

Active until May 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/grafana:12

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/grafana:12 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/grafana@sha256:783f12ca30ba8d7ec55604c5e8b23b7ec0d2830a212d317138818c9d86ef1c9d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/grafana@sha256:f07c7a3a38c34d18d0703055f8f1749b0fc47bc299c1735d1935b4999d647020
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/grafana@sha256:9e0e4b652051ce85bd7281d474aafc16d67cbac7d4da44630af21c6bb1eb72bb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/grafana@sha256:939929fc8d3dc72c46a8a1ef9519ad8d72377ea0dfd2f0d0e58aa4fafe6e9098
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/grafana@sha256:21e5366b82fc8f44fc1427859052bd8b10b985b25447f04811edc45e3b44e86a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/grafana@sha256:3023057b18b75311b595cac2b1ffa1d9b41a92d7c4f7babed7511425e3821f63
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/grafana@sha256:d7f469ef18871585a97d572e5b4ddb83fe862ab66a2871ef4a2fcc511a7b2b0b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/grafana@sha256:76c57e73e2c55ad11241ff956a920ee33ed8443453551ba75fe93e85e62a1ac6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/grafana@sha256:becfd74c9387292597046b0376a587fd279584cd9d7ef0f2d396a38fb71daaab
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/grafana@sha256:19fd68da962a03fc12f709f7e6c8acd5e826cf4a690e063feb05701fb9f57ba4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/grafana@sha256:e58ce81d48ed6bc81c8fc4f13d4134a5b9b5bb0a7ef54319c86edd9d979fab07
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/grafana@sha256:ddba8d074f92741a5bddc5e7f6d6f0939089056de95bcd326a1d60d460314e6f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/grafana@sha256:420c6a713fad44c53ed46f224f937d3c064f2cbea013591011d590b932a1ae0a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/grafana@sha256:7f5e437ac1f78154d85174fad4234d62e1c88f186438f324f9644db37595faf3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/grafana@sha256:89c08a9d5eab44761c40627a0f277ba32ebe8ea3c629811c01ea870241d685f9