Sign inSign up
Grafana

dhi.io/grafana

Grafana 12.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

12-debian-dev, 12-debian13-dev, 12-dev, 12.4-debian-dev, 12.4-debian13-dev, 12.4-dev, 12.4.10-debian-dev, 12.4.10-debian13-dev, 12.4.10-dev

Index digest:

sha256:0aa4a54773ab6ac755a6813462f33c1e74b462c4e83aeec0ddb0c3409fa23360

Manifest digest:

sha256:b602dbca743ea1161f8d682f1636ee8706dd3a0ee64557a7050d70eb06685862

Size

241.69 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until May 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/grafana:12-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/grafana:12-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/grafana@sha256:94a4010ae6a42c074ad3d27a5ee190d11553de2314d2d64c846aaa124b703198
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/grafana@sha256:8d599fc55a7cbca3899a9d097a680b1aff1e38713ed5db49049cbbf6aad46e97
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/grafana@sha256:40a09ddde1d1f981c823b00cd2e1e02a0d869a612a80aa9d2676162716395ce9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/grafana@sha256:afe27ad32f72e57f4d4df3a263ae574a3adbc96cd4f82ffb8022124ebf4f3c34
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/grafana@sha256:dc99d3ca278e4dcab9dbdc24656b5767b30d1a9b413700f607306d4655558e23
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/grafana@sha256:91bbea577eacc90271c5b4b42d91ff1de8490e99d59a00f30ac1e31f21f285fa
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/grafana@sha256:6cb3757d9acfdac15fea4724fd8be731eccd0b6a6d57daede7f348cb22ba53bd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/grafana@sha256:18b802c48121f7c6985458b22fd6a0304373cc45d4d6b3782d54dd4c4c9925b8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/grafana@sha256:f140867ae7873a9709e430189c83b88a77d228133bc6ecaaff4a501fd290335b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/grafana@sha256:01217b70448068804ef6ddcc5cb547c75cf088b80ceff55b42e2a8b7c39a49ac
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/grafana@sha256:bad6cc586af9d9d21a8113f382261ed634fc5ac0c85e10791e3bfc5316f5e816
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/grafana@sha256:14f03c969f48499d77afa53cd3deeb82a4689e65a469153d566a3cfea49d5096
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/grafana@sha256:c4fecec2c265486362704b34a2b984104e29095da4ebe6edeb02486a1a154f97
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/grafana@sha256:e7b0e9fd8624f5ddbdfd90af35f78b81a449de067ee1339f224f670b07ce13a1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/grafana@sha256:c1835889ed1e7c34a751e7af75ac4fa0e9f01f69c00c4261c2b803ee7c551342