Sign inSign up
Grafana Mimir

dhi.io/mimir

Grafana Mimir 3.x

CIS
linux/amd64
alpine 3.24
Tags:

3-alpine, 3-alpine3.24, 3.2-alpine, 3.2-alpine3.24, 3.2.1-alpine, 3.2.1-alpine3.24

Index digest:

sha256:9cbf5a574b1892b617b2eb731e08aface75b0d2f81424f1b5080f288a34244e7

Manifest digest:

sha256:681af5e7d41b682d52c1960e88dee43fd4405cc989d3b9c459a85c4e95e28708

Size

32.20 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mimir:3-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mimir:3-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mimir@sha256:e50548e7f7c60cb7f126fb90c7293cf3112059b0d1ee14376931314a85be66fb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mimir@sha256:41bf9e58a006a33f42095774eb9807a5a2586afdb0dea3ff68e7474fd0003073
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mimir@sha256:4ad7581bb25aceb7fdcf971af81bb724a1cd03553dd45952fa9f5d732a452ff8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mimir@sha256:167c961960e3540eacadcdd58aa1cf10f2079213e0f345beb4fd24a948c2dbfd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mimir@sha256:133f4a7f8783a52296707fbae9fab9d1315049ee4b61b09e262bbb68d257fe15
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mimir@sha256:7bdc25f759b98388a6169eae997a3b068cc891c65205cdc1438737eea090dfcf
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mimir@sha256:6041576372580671439d29a3854afb8a24561656167cd6fb13f4b8325d45dd00
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mimir@sha256:6eaa9ab50c6dbade0c483dcfbb7d50f3828893d7b35804bb7d1d44b7d760aa37
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mimir@sha256:b80bf18fe348505f7a95c9d5f52aee2448c2a730a6819944a420cde541dc94f4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mimir@sha256:ec4897ef862124bd1a3857e5dd20ba289bb8616dabde71e848831c557c99818a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mimir@sha256:ac4c5ed87883f3df1c4624bbb08c8d1c121cf6305773782b4fccf8899646c470
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mimir@sha256:b1947350bfa89e8d8c32a875ca3048558cd276284deb2672a2c44a6c8449ac81
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mimir@sha256:442d9bc9ff78f257501df237f7dd87ea107d8fe3d8ed36c6bbf6395cca7f9f0c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mimir@sha256:f230a5c22a70e8a079fd1c450b387a91c53738436190cc060cdb3ff08265d113
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mimir@sha256:ad967953e8e153ce38d79dc8a0d8829b78a8080c3a44764bde36c99bea6571b5