Sign inSign up
Grafana

dhi.io/grafana

Grafana 13.2.x

CIS
linux/amd64
debian 13
Tags:

13, 13-debian, 13-debian13, 13.2, 13.2-debian, 13.2-debian13, 13.2.3, 13.2.3-debian, 13.2.3-debian13

Index digest:

sha256:55715acdf0d0160d9fe66a68b10d9f16dd9aed0abea19c3e2685271ac0594999

Manifest digest:

sha256:2caa39c2323390097bc0d16e41ce4f2d26119ceedd7e5220fed43345b301e733

Size

256.18 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until May 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/grafana:13

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/grafana:13 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/grafana@sha256:dbae264baa5fe89a6f77ec473d6f2fc4a936da6056b975e23e482c30ecc56ec8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/grafana@sha256:899d2217689b92433c56466a3d30cdf7123ba4a944b8f85b6bc89be308205c07
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/grafana@sha256:366c7b6d8ed007e3172ea4c20a2fdb85ca6394c98280a99bfd5306a4030a6390
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/grafana@sha256:8c159e9d7d21ade03ed5c2b0ffda36f91a15eea263fe3cc7bd7a28a580069c77
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/grafana@sha256:a091099965d968c61cd377781703f4be9e63e20af6107105346f9435ad51c725
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/grafana@sha256:71916fbedbe771755db1adcd07421edbec8692f26560cfd88d16c653aa60a5df
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/grafana@sha256:5ab06a8fc5f0cd52599589f2891d2deabbd39c0a3c141ad98f9fba0fe8c521b9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/grafana@sha256:4e46acbc98f33dddfdc8fb590b0eb8ff791428e716e86b45efd932e866569e45
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/grafana@sha256:11b4cfb69de5e94ca859e81c23e315cb756e1ef0934892da9bef8fa05beb4c21
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/grafana@sha256:b6c53c0b3974d77f3ccf0d15c7f60120c6f1b3b7958505297ff7f0a0ad4d9ab3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/grafana@sha256:14bc8daaa8fc8b4f3f3b356311e0fed2eabf959da3f16b1cfaaf9110ee28deff
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/grafana@sha256:05ec2e356e1cdc2f6df8202383a8564f533ecaaab7d4353688330fe5173d5dc1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/grafana@sha256:6a1be6ff6e7ff82400aa5d98aed5d1e75970a7d440992bd3d375297009b17139
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/grafana@sha256:c01189b3d5dd92d54ada8edd60829ca20c8414a341685a06502663be6a3f06ab
SPDX SBOMhttps://spdx.dev/Documentdhi.io/grafana@sha256:f16b2bb025dd6404a6ef01afce617f494c41845db099761ba4421d8929eee6e1