Sign inSign up
Grafana Alloy

dhi.io/alloy

Grafana Alloy 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.20-debian-dev, 1.20-debian13-dev, 1.20-dev, 1.20.1-debian-dev, 1.20.1-debian13-dev, 1.20.1-dev

Index digest:

sha256:9bd8f37d86b2244e1cae58b40a0fb33fab7157614aeb7170d5c13a3a7c587483

Manifest digest:

sha256:42b8a0ea6760e25528157496f2ed35da196a098ba0f9ec77f69e3683db28d997

Size

117.75 MB

Last pushed

2 days ago

Vulnerabilities

0
0
2
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/alloy:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/alloy:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/alloy@sha256:18c5d19a98264efd1a82dd038ea1211d821bcc0c1410ead00ff096b69aa4f067
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/alloy@sha256:a9188a9679770b6f894657b8ce0fc0ac9e8717fe281e9af739500eb70d583352
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/alloy@sha256:5f15deb4ffc497455be473b0f34985050f6d2aa86091fa01862cf235f7c05182
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/alloy@sha256:3b25cf3a38bbcd9a5d9528f4d4b24937fd325e451902462caa3e755f09f4a923
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/alloy@sha256:70cef03cab6064e53e00aac89697ad751ef1f5c86add470160fb4d6f89833f79
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/alloy@sha256:3b9d588f7f3b5f9f038c84a676185a977163793255123f421ae0e13f1cdc98cb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/alloy@sha256:1f152c34f83590b51c231a91e1e88af0796e022b4f88c21f435451f1a6f2f7b1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/alloy@sha256:f6b93296f91351d7cac09ab63a9d6bf14595f15e99a6a9e5958dcb7b061bf5a8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/alloy@sha256:0e9babbcbf0b1f5152b174441e79eb4fb9d52c6cff95660ff5437cd247d2d5fc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/alloy@sha256:6f67ed62fc1654e4271986e1f1886c81426d7143da6897eb76f565f08a5a4ad6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/alloy@sha256:2b0fd497e99131edab41ffcae77bcc04c088244412d7717c3562d5bfb102ef29
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/alloy@sha256:974785fefd1528e6ea620e1b583ad6c0aa5a9186e50d7022ee061597e1cea06c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/alloy@sha256:4644b4aa93a79f3a599539b2bc08a0048c4a4b6a2497393ead79eaafdc1d523a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/alloy@sha256:b1ff89c4f9d0e7f557937bab6d633c47aa863174f8d4f4822e90066f05f43933
SPDX SBOMhttps://spdx.dev/Documentdhi.io/alloy@sha256:565668a555b6067b845b46e2fcfefc249274e93aa8c8fd42618a89d525a9739b