Sign inSign up
Grafana Alloy

dhi.io/alloy

Grafana Alloy 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.19-debian-fips-dev, 1.19-debian13-fips-dev, 1.19-fips-dev, 1.19.2-debian-fips-dev, 1.19.2-debian13-fips-dev, 1.19.2-fips-dev

Index digest:

sha256:8701de8f556bcc21ad119656ca8a9db36a356d548eeb691efe8437f32e3e9f96

Manifest digest:

sha256:6c25713c2b9a0de42a440dfb6a3f65d529c34288816111ca6d6c37abe5ce0038

Size

116.13 MB

Last pushed

2 days ago

Vulnerabilities

0
0
1
2
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/alloy:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/alloy:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/alloy@sha256:60316afe8a3aa7a68db1ea0e74ab248bb2615a80b3048ea10d35c885def7cb63
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/alloy@sha256:fb1193fd66feb9d5f3d4165e03c970bc774400e052195df3ac5cb70f6c9b5dba
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/alloy@sha256:d1db5ae5e0d92a9f82669f43555ac968e87ba0618dca59aaf13c419d66ccbcc3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/alloy@sha256:ce4901002603943f8e9453337cda6b7cdefb2b9d5826fa3cc0f450810ec9a4d9
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/alloy@sha256:44640444b67cf78a8e8a706d742b30812ffc15b2ff1e624360c17622b2c56118
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/alloy@sha256:6ab9f2d163a97d414a8318365b53d18a0f967c14ad8a5734be8ba44b09c11ffd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/alloy@sha256:fa2d4404e3f3375a01fd056590397f3803bf6b817c6ee102332bab443c454216
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/alloy@sha256:58749174395f5553eeb968a321931289200fd6253826ec39d8427068cb997041
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/alloy@sha256:f51e09b5ee5db354b2b1f25d1c57608272d97a3fcf80bac0668f1d5d2de08f50
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/alloy@sha256:0fa7ceca4699234dfb9a22e3146d91cfa23bf49db8bae95c8ef0f334ac5db15b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/alloy@sha256:7216e8014a949060fb913c6877aec3434ab1cbd68ca752e9bfc55fb96fb0a225
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/alloy@sha256:26780557c5baa8bd80b04091a114a75d42561175dc165072ca9975749806a34e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/alloy@sha256:980a28d1dbfe30379a3df90c5910ceffff2ba7b2d2aea834924f889db2eb5f59
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/alloy@sha256:5d87d18ebb4b5c2a3c2bd450aa666977ee352972272717df1c138f15496d57f4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/alloy@sha256:2fc44a044ca3e0cd32476f1b88e3392ad7028aa0a3f22f68741fd9b777f380f0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/alloy@sha256:3276ece9ed87d4f4b059f21580d8eaca9c048867d484805669e034cf2f51a6a2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/alloy@sha256:fa6358add8b93555b5f0b0ac1e62272778ab80f438d118fd2095c44643127982