Sign inSign up
Grafana Mimir

dhi.io/mimir

Grafana Mimir 3.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.2-debian-dev, 3.2-debian13-dev, 3.2-dev, 3.2.1-debian-dev, 3.2.1-debian13-dev, 3.2.1-dev

Index digest:

sha256:89448690cbbf8c7d3fc549a5c5d3ca7d8c325db192a06546afd53fbc78444404

Manifest digest:

sha256:de96387bffecc689d3835cfe3461f9d64f0e0a11f0ff67fa43f10e2ab942871f

Size

85.04 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mimir:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mimir:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mimir@sha256:1f7f82576ec1e41ce6d5984941c8f8f1672681b5b2d393015476665be6356480
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mimir@sha256:1b4999c7bb20f4c6aa18b4e7679464f8ffaa274cc29a3f216c679d0dc4223dde
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mimir@sha256:983eb2f9cd13176a568771f77fd643f80624b5db77eaeac92c6ad4dd317ba54f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mimir@sha256:5f9677e4b448f5709aa143ff2ea02a90fae3b90337cf241106e429cc42012e5c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mimir@sha256:5669bee78118467e2409288bbcc7f9b87f717013448bd41668b788e2e413fcce
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mimir@sha256:b1eaf2547b3f3194d926d94aa8f4995ebfa81d287cde11693cfb3565535d6ae3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mimir@sha256:680e3b948aff5867522f8056f177e682c53e5156dc6ad3a49dc34867c99bd1e0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mimir@sha256:8f43b7bc8cea06f2eab49e946ffedcd79296db44617733f5d95bc6aa554ba6d7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mimir@sha256:07d9e6164cb09c7027b742ef0bf8fdc5794d2a5c4b2ac993ac27db52a9f02ded
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mimir@sha256:ff6498403728e3cfded7f53254e1cf3018cbf4fa5b6789b42cda5b12fe2fb067
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mimir@sha256:a31641842317b5756e3442d2c5cea24de19150478c6cf135bcc90c2eadbfe8e2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mimir@sha256:629746da408aac53ce17754e30af4677256205f8249f34fd07acbd5199589e72
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mimir@sha256:ebdf5c0843535218e60e637578987ead3923340caebd7a34602c9e2fbd151933
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mimir@sha256:c6e0bec86ccea3a725c6e1369df108608cffd6ee50a3097898bf979009ac5d64
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mimir@sha256:74473be6eb6e372d28df39cbffa0f80616865674cbb6e7a7f85bf3cd342ebf0e