Sign inSign up
k6

dhi.io/k6

Grafana k6 2.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips, 2-debian13-fips, 2-fips, 2.3-debian-fips, 2.3-debian13-fips, 2.3-fips, 2.3.0-debian-fips, 2.3.0-debian13-fips, 2.3.0-fips

Index digest:

sha256:23e49984935e01d416865db421e9018f9828a01f50a3a985bb61e6c6b5c37d8e

Manifest digest:

sha256:ef5e70489ccb810612f6eb403d4923cbf0e2a2ff3bac9e41f82c4cfcb92b4d7a

Size

24.11 MB

Last pushed

18 hours ago

Vulnerabilities

2
8
0
0
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/k6:2-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/k6:2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/k6@sha256:9d5bce9c5e3324b00248688ffd52e9f6416802fbe3d87f87d72be134434950a1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/k6@sha256:dfee4440c65559668b2fe0e077cad117c4d0175fc5d645b7bc2c5e628447e25b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/k6@sha256:f9580841e38aa26f1ef321d052551bd7272626ebcc9f0247034790c8bfcd09f3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/k6@sha256:374e5615f142b5ca10ffff1312ddaa380201e401b98f0c52f84a5bf077fece04
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/k6@sha256:6368a789b1eef54b58bb9151a759037be63b049588977792fa72a9570e77332f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/k6@sha256:bd92bc79361017caa67ee59b5c02c1609a4b739580b15b4f046ff6353e567e00
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/k6@sha256:32a1badb62316a5f80d552486acb186cffebcf8d0e009e70afcf16244297b4bf
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/k6@sha256:934f65cdb11cbb009e4fc743c890a0beb0cfd3899243befada42316220acb902
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/k6@sha256:c6b86a31c7c43be80051d4c4cd4b475496dfff5bf57d1f4d6f31cd9e3a463158
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/k6@sha256:bf93a8a7cbad70f53851179a2ba351bb145b8be69b53e168aa6ff438d5bda830
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/k6@sha256:1f4c89b8e689623ce5e86d9c7ad8c43673453730c020260f6422b032eaa4561b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/k6@sha256:ba51e1654ffff09cb57bcebedd29b4e3a99b478ab376c3be66ddb746ca7e46d9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/k6@sha256:4d9fb9065a297fa028b696c4c5f2adee93b1d677152a4a104a22eac3173df24e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/k6@sha256:7edec1429643253e5066298e3656eed48d3381be115954483ca57005724d1f21
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/k6@sha256:d1d862c3957c3ac4da5a6604cf353e1a728b99dbaeb86b3bd662a51b662c98b4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/k6@sha256:cfd0eb4002b1b922ae9f331ed255cceea5332b65b944881ba41117b430686410
SPDX SBOMhttps://spdx.dev/Documentdhi.io/k6@sha256:393be13ba4d052c567bde7d7deb6001e59085d883f915b3b722d252e18c2155d