Sign inSign up
Grafana Mimir

dhi.io/mimir

Grafana Mimir 3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

3-alpine-fips-dev, 3-alpine3.24-fips-dev, 3.2-alpine-fips-dev, 3.2-alpine3.24-fips-dev, 3.2.1-alpine-fips-dev, 3.2.1-alpine3.24-fips-dev

Index digest:

sha256:74a1cd803b61c49f6221332f98508810579d2aaa4133a948329abb8659febf41

Manifest digest:

sha256:e43c02e5e622f2159c77742ff8f98bec7f0d17597a30f313d4bac4906c44361d

Size

66.27 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mimir:3-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mimir:3-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mimir@sha256:ed818cf06931911ed8eb1b13b9d6789659541842ebd6365ae9cc594e921803cd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mimir@sha256:0a7a81d394c7f9a5bc8e74b1a747a7e322560b326e59a3441e64ddd1462748ef
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/mimir@sha256:de8a64e5f300ea9cd9ccb6b3661d1f51ff89d96eb00a92c467adbf66eebaadb3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mimir@sha256:80cd29d9e46859769ae5de090aaa4336020b8b7c5b07ab6fb7596f98d2a12d9b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/mimir@sha256:bf3abe31d0370cd4420eb17f52828fcfdc19b523b9560eb99e5be238ff7219e1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mimir@sha256:6bbddf5c9ce8746b8957e07a9327dfa78a27554d78f9e358ad423f3f58382328
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mimir@sha256:dac7f72d04368f5d487f17a9db8876d17523bd4a9163a3cc32e58de8b159dbaa
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mimir@sha256:50059501d8f0348c16f565d3b94e7142f88e937b3a04603310c4cdbf31fabb16
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mimir@sha256:241a2819397100962ecc55d8491772a8ea3b3f8fa897f6405bf5fd37abebb3d7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mimir@sha256:9a8f5c4f1c92816d2ec967a92b03526ee12de806b70685df70506e654d72ba44
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mimir@sha256:c3f5c92236ca1d6ca103af85c69217f75ede0fe9988857af0cb452ec7dd5e51a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mimir@sha256:41eaab239aa23897aa428199e7cd5a5d99debfefdf3f5d6bdbd291e9a987f206
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mimir@sha256:8edce2ae4dede8d3c67fc73bd1798638b9ad075dd9dafc1de9c531b3e83bec3c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mimir@sha256:73476e10a95b8262494ae72c64ebf3267d6afcb3633569428d3aea356023901c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mimir@sha256:1d5268eb7410d1043bb22dcf012c1a638891c1a9f990bf8159de11b9db609874
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mimir@sha256:9f838c852bf36ad3e80b5f1c2cba8b63c1f3093cef50e7819646bf199b1db8df
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mimir@sha256:bb8fb8d70b4a8abf726f67bfdde1661fac968577ba07e77692787513f11250cb