Sign inSign up
k6

dhi.io/k6

Grafana k6 2.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.3, 2.3-debian, 2.3-debian13, 2.3.0, 2.3.0-debian, 2.3.0-debian13

Index digest:

sha256:e0612f2d9b75403e7a9c64b5b34dae68dee8af9ac3dc8eb599b5baf93c649a2d

Manifest digest:

sha256:459b38d7c1f2c9d88bf7df9ed41447a015f855fb4e693b89e9fdfe3e834d8adb

Size

15.91 MB

Last pushed

18 hours ago

Vulnerabilities

2
8
0
0
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/k6:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/k6:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/k6@sha256:3905451bfb6a9d4bef57864e5c31521abcaa5d51fd3905a18b1a5bee8d307a1c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/k6@sha256:6dcac22db9d161dc0b1744341c8e2cb116a13b37a1ee2605536f66b02919f61e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/k6@sha256:71e13b290d8a1093125d2e9012d2615f3a661581d2cd010b2a76df8597e0fc87
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/k6@sha256:f630b054f87a4d082f30d08733b8c5b16dbfe5a39bda1d039c0f3878c56169b1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/k6@sha256:691810d389345ebfdcc4969312d8994ce1b56e0bedeb1823c673da89202cb0fc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/k6@sha256:b0529eb20310942dc253f0d54ba446d7b248c80d0c29aa80627a65867e27ee9b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/k6@sha256:77bb4a63a1dd56c15e9abb7666e0b6980216f2276068d1bb2ec346d18b219861
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/k6@sha256:bd7953b4690949fb23cfc46aa038b629faa14ae7f5f95ef01e477d3a66e28911
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/k6@sha256:b58e9265a33749d4bd6ab003bf54320dd4d0bdc4c4b69a7575f32ac4db3c97bc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/k6@sha256:ed50033acb06be392213600e66b4c55a2615d7d74d2d0d2396b846fbd3dc7dee
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/k6@sha256:c72e3de452e1407fc5eb429a8dd9d1acc7d6c0be1b612569e4a600b024e0acad
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/k6@sha256:8db12213d682d41cb0b2bd7cae11cab4bedae8ff8f58ea29bdcded2f538bf2e1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/k6@sha256:04d70a7269aaa98f5d39aa745cbd2a1833cc6deafbb734a2d977c8362fb60396
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/k6@sha256:00981a615aabd3c95516d9a10738718fce416263f836eaacbb33d841484302bb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/k6@sha256:a48f497770aba87addfb1657b720ffeaf9ea0751dbcff52530753fc05ee282a3