dhi.io/alloy
1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.19-debian-fips-dev, 1.19-debian13-fips-dev, 1.19-fips-dev, 1.19.2-debian-fips-dev, 1.19.2-debian13-fips-dev, 1.19.2-fips-dev
sha256:8701de8f556bcc21ad119656ca8a9db36a356d548eeb691efe8437f32e3e9f96
Manifest digest:sha256:6c25713c2b9a0de42a440dfb6a3f65d529c34288816111ca6d6c37abe5ce0038
Size
116.13 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/alloy:1-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/alloy:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/alloy@sha256:60316afe8a3aa7a68db1ea0e74ab248bb2615a80b3048ea10d35c885def7cb63 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/alloy@sha256:fb1193fd66feb9d5f3d4165e03c970bc774400e052195df3ac5cb70f6c9b5dba |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/alloy@sha256:d1db5ae5e0d92a9f82669f43555ac968e87ba0618dca59aaf13c419d66ccbcc3 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/alloy@sha256:ce4901002603943f8e9453337cda6b7cdefb2b9d5826fa3cc0f450810ec9a4d9 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/alloy@sha256:44640444b67cf78a8e8a706d742b30812ffc15b2ff1e624360c17622b2c56118 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/alloy@sha256:6ab9f2d163a97d414a8318365b53d18a0f967c14ad8a5734be8ba44b09c11ffd |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/alloy@sha256:fa2d4404e3f3375a01fd056590397f3803bf6b817c6ee102332bab443c454216 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/alloy@sha256:58749174395f5553eeb968a321931289200fd6253826ec39d8427068cb997041 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/alloy@sha256:f51e09b5ee5db354b2b1f25d1c57608272d97a3fcf80bac0668f1d5d2de08f50 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/alloy@sha256:0fa7ceca4699234dfb9a22e3146d91cfa23bf49db8bae95c8ef0f334ac5db15b |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/alloy@sha256:7216e8014a949060fb913c6877aec3434ab1cbd68ca752e9bfc55fb96fb0a225 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/alloy@sha256:26780557c5baa8bd80b04091a114a75d42561175dc165072ca9975749806a34e |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/alloy@sha256:980a28d1dbfe30379a3df90c5910ceffff2ba7b2d2aea834924f889db2eb5f59 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/alloy@sha256:5d87d18ebb4b5c2a3c2bd450aa666977ee352972272717df1c138f15496d57f4 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/alloy@sha256:2fc44a044ca3e0cd32476f1b88e3392ad7028aa0a3f22f68741fd9b777f380f0 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/alloy@sha256:3276ece9ed87d4f4b059f21580d8eaca9c048867d484805669e034cf2f51a6a2 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/alloy@sha256:fa6358add8b93555b5f0b0ac1e62272778ab80f438d118fd2095c44643127982 |