Sign inSign up
k6

dhi.io/k6

Grafana k6 2.x (compat)

CIS
linux/amd64
debian 13
Tags:

2-compat, 2-debian-compat, 2-debian13-compat, 2.3-compat, 2.3-debian-compat, 2.3-debian13-compat, 2.3.0-compat, 2.3.0-debian-compat, 2.3.0-debian13-compat

Index digest:

sha256:a30e55b716dd74b7fb8b0a64570cc108e988b54db369dcd0325f693ea4cb0656

Manifest digest:

sha256:6406e8eaa794f3c4aba50742d0b4367f4dc11ad8025d9077ebbf9fa2c9c835dd

Size

25.13 MB

Last pushed

16 hours ago

Vulnerabilities

2
8
0
0
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/k6:2-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/k6:2-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/k6@sha256:03649e7a95b62c76b532b3788d2633fc69a16398b33c601e9f6beacfb8fe1b8d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/k6@sha256:e6a846d30db37fe6a0d56726c878aa1fd96b5821a87aa7a8df6a4302712f0d80
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/k6@sha256:d46a51bd3ee24ed77c7bf95d76666eedb621d5cae8dca904079a42e8043bceb5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/k6@sha256:5536f65f954b369aa81a5980ce2aa055235d4f468f56492b3492fcc9a0858c7b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/k6@sha256:1d2c24c7e26ef82c2e3612c07c5be8010b215a2ec38d6980340851c37a0d621d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/k6@sha256:7cf7ebf86b9fd917b478642f8b9a48f89ac58fe80cbc9c65953770280aa10a6f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/k6@sha256:9be6e1c6993cd553cba379b4c37010fbf1cfd1f2ee912c7fd74d9a5ef2f6d62b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/k6@sha256:0c788769550af35f054b9ff40954bd6250e7a737fa34e13ecded50053415d540
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/k6@sha256:9ebba5ddfb67a83a03fd68f5edb710bf2a7b7f0d11e3fe2214ecc57f2b11d878
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/k6@sha256:af5f1c400eefa12f1c4d3cbc6e6d4625a901ab061674655c280a5858a28037b5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/k6@sha256:e75203491354729eb6338871f7fe0dbd7ccc3c99bdb4cb01da5b1cc421fe07d3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/k6@sha256:e6e451a92234e0ae3180b4c6b25bf07f454df5d9929a21923df30c0942de7bb9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/k6@sha256:25aac79ded86db7de703337f39c7ea6ea73a7e04bb40c015d959871a8ab8043c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/k6@sha256:04c052cf3f6913edd01ce73baff314a92c9785c2faba35753d2a3fcb7c39234c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/k6@sha256:e46276dc46ef94738b316594f1aa05c3ebdcdd449f9ff3afa607121c4c87fb2b