Sign inSign up
Grafana

dhi.io/grafana

Grafana 13.1.x

CIS
linux/amd64
debian 13
Tags:

13.1, 13.1-debian, 13.1-debian13, 13.1.5, 13.1.5-debian, 13.1.5-debian13

Index digest:

sha256:5ccbb259ea15538cded97ad1aa71a57ceae01a8f44e1b0066a838bccff12fdf5

Manifest digest:

sha256:d62364202ee70fbab5b03d8eae3dfaa3b20c14b170d06b284385790315d70902

Size

264.26 MB

Last pushed

20 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/grafana:13.1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/grafana:13.1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/grafana@sha256:f0f800a3c6a43ba186668f9b9aa1390193355bcd09cd793606dac1f05f134b42
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/grafana@sha256:879379143815be27553a991967b4a5b5f21ede211a8c3736c5c4ba18520fd8ee
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/grafana@sha256:20956233865c92ae705fd7811b0202eb1e2944514902ec1a896ab75c81fd0dc4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/grafana@sha256:3910f483acf797210da70beb6415f8c7ae041df1bc3a7b5848db7b7c4df7743b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/grafana@sha256:2dbef6644cd1efafdd96d347f14714f8fbd12bf9a3fb0c7adf59f2c8097d1773
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/grafana@sha256:eefc675f3e831e18f3def5213defdfaf93c8537e8320e98cba20066642652440
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/grafana@sha256:320b201977811f78fea6e6ae32e0dce048f2ab8fa49d760fa11529c2f8e0bd61
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/grafana@sha256:f9396a4ac7fee83197ca9fa9ecb2f164426abe8a459c04367dfe1e1f6859102e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/grafana@sha256:456131c233178563fc2643155eee0ffce4d17fb0926cef78a932b5978518f8d4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/grafana@sha256:10fe97782e3f95d7b7817aeacc86625781157fe111758d5730131acfc14734bb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/grafana@sha256:70c6cd7af5d61d1f8447cd2990daa07fd299188f4ee17c808d86b04d60a39808
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/grafana@sha256:0a65eaabc9626df0a86561bba760a258a0fe0ea8702f112d461d4b87b584c290
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/grafana@sha256:a0df4dd04be69246597edea27b3db92b967277262d36f294f614fe2324eb7fb7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/grafana@sha256:6e4070275e1d6307be058e05ec5b7e807ea96cce6580f3cf3abb19bc7de3f1a6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/grafana@sha256:4c285289285c1918bfe2d1228bde2e8356da54c206de6be9729220ad22f0c0cb