dhi.io/grafana-operator
5-debian-fips, 5-debian13-fips, 5-fips, 5.25-debian-fips, 5.25-debian13-fips, 5.25-fips, 5.25.0-debian-fips, 5.25.0-debian13-fips, 5.25.0-fips
sha256:30c0f5b7bf203eedff37944de5cde8cfcd52a1343c9d0b8902bca48cef4f4e04
Manifest digest:sha256:1d4c3c632dcb7f2fcc4b33a9fe8c36d78018fb3317bec728797bfbc22733ff3d
Size
24.09 MB
Last pushed
4 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/grafana-operator:5-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/grafana-operator:5-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/grafana-operator@sha256:6d86cb3bd6fb9f990497c7005f83baf30d773537fd979cffee35258b3f1c1f41 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/grafana-operator@sha256:5784e7e809c27baaf9200af43b1666369edfa5041324db707497e03426db09c0 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/grafana-operator@sha256:669ff6634ba5e03d025f4132a9c1bbfc3d749d14c3811427230ba52473664996 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/grafana-operator@sha256:a6ec98bf0002f7e6f56b429473d4867ea4826303f7bb8bbc0ccf286f287d230c |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/grafana-operator@sha256:731f52c92eab6c6be2e5823f510b98143a4ab160d19b032551eb998c456f5cb2 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/grafana-operator@sha256:72575453f21d506d1bc893b5d95b3f7d948ebb5699b9ccf366e742e7b02630a4 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/grafana-operator@sha256:92ebcbb6418b53ee897a97d71a37c639d27d3285f186ac3532f91fcb747d6184 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/grafana-operator@sha256:693bbad7390cbbac2608566cb75eb7fe52565da9be56785e284eabbd34e96a73 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/grafana-operator@sha256:d8b168cce69637bd2b08ed0d88751c313f84ee61feb77e43666ce0bac81283c7 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/grafana-operator@sha256:d6cef3a73d515f9e4b383f92a2872b03eb93596f51015c28a34e12552c03fc55 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/grafana-operator@sha256:29b54d0205e74ff1ea5fae5b249e51718372c807bd0742d14f7cc5bc8d51055e |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/grafana-operator@sha256:4357dc3c1d473e4db9ad31df00bd266b2d0c93f16d231d27fb802c235fc02f2b |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/grafana-operator@sha256:ec077f1ae2c26adedb693b9a9353fc531a4812ec793db38b4f496c1f97046492 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/grafana-operator@sha256:5c07abe0d9d1125fe12d6edc0f36ea358d60e1e19b591805b27f5bc2b724b667 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/grafana-operator@sha256:02c4c7c82002282919d58ec2d741170fc0ac207d9f6116e0f4accf63136d65d7 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/grafana-operator@sha256:7cdb73cb36ba0d59b8ee256df2f1dd227b01c456cf2cfc506fa2270b8b3b72bd |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/grafana-operator@sha256:70a9c432782bf9d67609ebf8b6ece08959c3d6fede3d8d4c16c246749bc9c715 |