Sign inSign up
Grafana

dhi.io/grafana

Grafana 13.1.x

CIS
linux/amd64
debian 13
Tags:

13.1, 13.1-debian, 13.1-debian13, 13.1.6, 13.1.6-debian, 13.1.6-debian13

Index digest:

sha256:f355a43312d7fb73d9b748bf95ac1dd69b138cd6a2c13443d2d3e9f1dceb0b2b

Manifest digest:

sha256:6c540d6628aac94455755dbdbd4ad5d2a9b4acaa534e093f8a2605d5a1ed58ee

Size

264.28 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/grafana:13.1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/grafana:13.1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/grafana@sha256:73d9c39c70eaa51b0c5b9ce293a25446f772b50075f0ca8c917c88083d989c3c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/grafana@sha256:5f18cf93bbd3b7c5efebda9229adfc1788d4466ba89f71b4f52aa2751e6994c6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/grafana@sha256:6d854dc3660b7acc8e02d55dee0bd1be6094652e33b13a5b838eb04f9cbfe15b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/grafana@sha256:e6df4ea0168229dd3fb89c63642569f01f97486325a8ae6043b05e98ce614026
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/grafana@sha256:e9362822f6abc86f3d1f588bcfdd10534ecb6065aa4031ec88cd7aec5306ba9c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/grafana@sha256:a2b5476217d6665be75022f7900e52245c8434a08c11e21a19e50fe9d968eb1e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/grafana@sha256:e27e1272648eeb941267925f65ad8c937826d7485eceaac1aade8cc7f42866c1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/grafana@sha256:f2ff431c03e08a071f13bcc24c7e59ca59bd92abaa254ebdcdc2bc074d284d22
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/grafana@sha256:55de3cdbf78fb7f73278b7130447355cadc82f57e91f490bea5e6a9cd2ed3e55
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/grafana@sha256:e339d894f84673569f2ec7e8e92956e8b2b47712d7c2a4fa7cc30a526f94f8fe
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/grafana@sha256:4b366dc38572d926d0af61371fba7746e46b7d35a071b3bbe4f2e8f0ce80f794
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/grafana@sha256:30c9c9870a639301dc771972237e6d21b5f6e7fad0965d6cb994001294f7c0b5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/grafana@sha256:ec1888bb556fcedb11dc8a33944409206e45d0967c96403133ef35194832ab7b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/grafana@sha256:1beadd3297690110046d5ea49f5e65a1ba51539738b5fa191a048c4feeb70940
SPDX SBOMhttps://spdx.dev/Documentdhi.io/grafana@sha256:9be1cd3d04578401bb5e42fee06a806cabc2313d9ce1da81fe2721382a2c003f