Sign inSign up
Grafana

dhi.io/grafana

Grafana 13.2.x

CIS
linux/amd64
debian 13
Tags:

13, 13-debian, 13-debian13, 13.2, 13.2-debian, 13.2-debian13, 13.2.2, 13.2.2-debian, 13.2.2-debian13

Index digest:

sha256:1b7d321a35a9bdaa34be2dbfe57dac9a0c9c31906322b2cf41c3b7f33d0e46f9

Manifest digest:

sha256:4ce247d8c0a296689e5893eb54c1bc2da19bd8573ee1cb1204fbee08f60b1afc

Size

255.46 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until May 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/grafana:13

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/grafana:13 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/grafana@sha256:2aafc3da7c3bcc01230b7b4b9d3a991eee932a38c3e5a9c3b60e9b5505783991
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/grafana@sha256:85d3ab2081e48b4cbb690e4e1645c762de92e9eae045337829c8a31fc111b4b6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/grafana@sha256:afe4af91f38436af538359296d93798ef421021fb1df1ca0a0562ff14e76a946
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/grafana@sha256:3c0c7e7bc00d233b1899829f36445400708d305a2998963738e9e4fa9e0a81a3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/grafana@sha256:eef172bc4e11823f64dcb7c308206108747992d5ffbee4b8c24b2e1f68ddb674
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/grafana@sha256:377cb66e8376b30de7061677256c40d3d8bb84c702c265e451a3a58e9b862d29
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/grafana@sha256:e3eae65cf456887b2ecc8d5c6f9529fe93f7bd23335760832c5e0338d9c4d6b8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/grafana@sha256:7da3545f110f17992ae695a975c99691774fc8c476f76f14206470ff4cfc7e52
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/grafana@sha256:4c911b99aca100f95ab96f786ee401fe99a6fb4d538e61b0d4c8285a6415cc1e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/grafana@sha256:ee3e71daa4c0e182dad44d4b48501a7b364f52b351d63264c48c81d0587ce854
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/grafana@sha256:c1672335f5215146eb66381c38414119bca08d3d5ea283813364a2d3c50c8c6b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/grafana@sha256:bd0400c1384b817021a3558df0d630cd4bf07c34d4aed6491f69d55aeb1d31f6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/grafana@sha256:9837cf5c1ff7451da64c4c709ca24d644b1e9d939bce887ede53f7f08b938b27
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/grafana@sha256:0df6d64e1909afc2f665a7f938acf9a62463de16ca905c3e78388a47afd37f74
SPDX SBOMhttps://spdx.dev/Documentdhi.io/grafana@sha256:1c490764feb72cfd70fcb51756a6b82b809b2e5ee17e5baa905ff94179b40b6b