dhi.io/grafana-operator
5-debian-dev, 5-debian13-dev, 5-dev, 5.25-debian-dev, 5.25-debian13-dev, 5.25-dev, 5.25.0-debian-dev, 5.25.0-debian13-dev, 5.25.0-dev
sha256:bccfcc5a8076de3d91cd6c01b0f366df84efe4c6aba379fce715301bd7f2024e
Manifest digest:sha256:1ffdb0ebede9fb320d8b0cb94808f7b784a243b710b0a48ee8134b7256896eae
Size
53.81 MB
Last pushed
7 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/grafana-operator:5-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/grafana-operator:5-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/grafana-operator@sha256:3622aa1efe6ba64b7654676b81fa26ccbf3d07482d88200f1ef5aab2111b00c8 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/grafana-operator@sha256:ffc640702ba08177919b6b972bc71b981d019194cba63bf1380ab2fa5ff6113c |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/grafana-operator@sha256:02b260e7d985ef7e9df55ce0a24cbd5967ca28d6ab4b4ac4e5010670303823b8 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/grafana-operator@sha256:143f07321f0f0c2f7fc9cfccf4416a8c3395ad38c47cd18bba01abade82418cf |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/grafana-operator@sha256:7951d71b76184d9bb651ee7cf8f67c8becd42d2e7b595dfe5657afd011b8778e |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/grafana-operator@sha256:37c2f1c5379ab90e377bde3972cac2dc775d133bd6f283969d9a9b0e52508c2e |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/grafana-operator@sha256:9f3f4ab91405ec2cde6101787e80bfadd7fc82fcc00d1b162c3bdbc5ad120dd6 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/grafana-operator@sha256:8038b1349e45dde7985418e534100034fd4a33e9efa21d6e8e0a0b2b6bc1d7cd |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/grafana-operator@sha256:d8c8aba01ddfd2bf22a87ac8fa6b27d705b5deb77b780e2e8ae669014d6de94f |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/grafana-operator@sha256:2793469ffc20fc94521295417897206901e032de29ec8f29f960550ea9d87da6 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/grafana-operator@sha256:fbffa423cd08d6439e5556b002243bc8fdbb6cb0b73d27df71a192c32c9678f7 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/grafana-operator@sha256:886ab0cb8ded0db50480e77240dab999fcaf5a827a403159f0727e4bdd56cd40 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/grafana-operator@sha256:745b0620875f05f4bd697a68f00728bd4136b2636f06309a0941aeaaf36350f2 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/grafana-operator@sha256:d2819f1db9999769d2b5f7fe50f78c2deb5ab75bd48a20add5d80ca8acefd08c |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/grafana-operator@sha256:5b719c7752bd3434912d553d99795cd8cc631bf0cc7bd74d0c423ba77408098a |