Charts / Observability / Grafana digest pinned cosign signed SPDX SBOM SLSA provenance amd64 · arm64 Rebuilt 2026-08-27
Dashboards and visualization for metrics, logs, and traces across many data sources. OSS edition, licensed AGPL.
Version
The latest line lives at the base page; older lines have their own page so you can pin and verify exactly that version. Only the most recent releases are listed — an older chart pins an older image digest.
Deployed image digest
sha256:3ccc56791c8a7ffc7a54a69084012900aa68bf3ef39a25095241e0867f416492Chart OCI version
oci://ghcr.io/quenchworks/charts/grafana:0.0.12The chart pins its image by this signed digest, so you never track it yourself. Signatures, SBOM, and provenance attach to the same digest.
Architectures
amd64, arm64
Runs as
nonroot (uid 1001)
Security report (Trivy) D· 0/100 13 fixable · rebuild clears them Full report
Vulnerability detail grafana 13.1.4 · 14 CVE CVE Severity Package Installed Fixed in Title CVE-2026-21728 HIGH github.com/grafana/tempo v1.5.1-0.20260427112133-525d1bab07e0 2.8.4, 2.9.2, 2.10.2 grafana/tempo: Tempo: Denial of Service via large queries CVE-2026-28377 HIGH github.com/grafana/tempo v1.5.1-0.20260427112133-525d1bab07e0 2.10.3 Grafana Tempo: Grafana Tempo: Information disclosure of S3 encryption key via status config endpoint CVE-2026-43871 HIGH github.com/apache/thrift v0.23.1-0.20260429145742-d2acd3c49e58 0.24.0 thrift: Apache Thrift: Denial of Service via infinite loop CVE-2026-56854 HIGH golang.org/x/crypto v0.54.0 0.55.0 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authentication bypass due to unenforced source-address restrictions CVE-2026-84304 HIGH google.golang.org/grpc v1.82.1 1.83.1 gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, in ... CVE-2026-84445 HIGH google.golang.org/grpc v1.82.1 1.82.2, 1.83.2, 1.85.0-dev.0.20260825072537-93e31b48545e gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers CVE-2026-18374 MEDIUM glibc-2.44 2.44-r1 2.44-r6 glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string CVE-2026-18374 MEDIUM glibc-2.44-locale-posix 2.44-r1 2.44-r6 glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string CVE-2026-18374 MEDIUM ld-linux-2.44 2.44-r1 2.44-r6 glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string CVE-2026-18374 MEDIUM libcrypt1-2.44 2.44-r1 2.44-r6 glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string CVE-2026-56855 MEDIUM golang.org/x/crypto v0.54.0 0.56.0 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages CVE-2026-78662 MEDIUM golang.org/x/crypto v0.54.0 0.56.0 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding CVE-2026-84303 MEDIUM google.golang.org/grpc v1.82.1 1.83.1 gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, th ... GO-2026-5932 UNKNOWN golang.org/x/crypto v0.54.0 — not fixable The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues
Close
Security report (Trivy) · image grafana 13.1.4
Install the chart Deploy to Kubernetes with hardened defaults. The chart pins its image by signed digest, so you never track it yourself.
Install (latest)
helm install my-grafana oci://ghcr.io/quenchworks/charts/grafana --version 0.0.12Deploys image (digest-pinned)
ghcr.io/quenchworks/images/grafana@sha256:3ccc56791c8a7ffc7a54a69084012900aa68bf3ef39a25095241e0867f416492
Chart version 0.0.12
App version 13.1.4
Chart license AGPL-3.0-only
App license AGPL-3.0
Service port 3000
Signed cosign (keyless)
Values schema yes
Last published 2026-08-27 Verify the chart
cosign verify ghcr.io/quenchworks/charts/grafana:0.0.12 \
--certificate-identity-regexp 'https://github.com/quenchworks/.+' \
--certificate-oidc-issuer https://token.actions.githubusercontent.comTransparency
The chart publishes its attestations on GitHub and the image it deploys carries its own on the same digest, publicly verifiable with the commands above. Both log to the Sigstore transparency log (Rekor), which cosign verify checks for you.
Upstream project: https://github.com/grafana/grafana