Sign inSign up
Grafana Alloy

dhi.io/alloy

Grafana Alloy 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.20-debian-fips-dev, 1.20-debian13-fips-dev, 1.20-fips-dev, 1.20.1-debian-fips-dev, 1.20.1-debian13-fips-dev, 1.20.1-fips-dev

Index digest:

sha256:a78203df700de75c1d2e4543a20b4cc3895f17a6e9a24a1db7f6171d699ab03c

Manifest digest:

sha256:7152805c863b6e8dc22870347e4f510cdaf992f15a2d8e6c47b530ef4c4fdb44

Size

118.59 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
2
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/alloy:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/alloy:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/alloy@sha256:afc15b249b99ab45119b6670f8a91dd1df125475ca798c70a4be67e10fbd506a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/alloy@sha256:706aa0e2ea1a5ad9ac1c9e868399efd979e74b3e8a1247bc3ccdbf2791048eb1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/alloy@sha256:5e0105ddbd134789ae1801ad804c268c7426fe52d256f4bbf38d99ab591391cb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/alloy@sha256:f15399e2c293f43d4f112797f020de25ea8712f6f4146116fa77282534df7151
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/alloy@sha256:31be207ad7ad7c99608c6349664cd652d3593081e6035d12c5538dc9c8187954
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/alloy@sha256:6a5f022ccaaa8b0a4ee4331aef753d20346d0223a5391af4335d493ca1976ff2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/alloy@sha256:8525c7b8f567ca2978db1bb31e65064961f32eaf9f816da12e4d24baff791f82
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/alloy@sha256:078d985ad25c85e467004511a99da5fa6676c6eb9b66c353d5b5f4f46e6626c7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/alloy@sha256:6dcd5380ef8177bcfe6a20967cc50b5b5ccdd54ff993fa10727d24fb9176ac2b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/alloy@sha256:7c65a7dc7493991bf88618f299524d74bd1953b4a06bbbc77569432c5d83218f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/alloy@sha256:9c7db4029c771c400f7da96aeeb1dda1d09a7e5dd4091a6335b99569ca4533dd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/alloy@sha256:b870e4d5f4c9a1009e84594d3cd30411609541582beb46c027b38eda80fb01f2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/alloy@sha256:95125baf7f7cf3633a211e34ef5f505f6b9075a7fc996d973ae1f4476ee70248
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/alloy@sha256:93416c7d9d5674ac2c80350f2601b070806aa79910277de756cbcddbe2d39a47
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/alloy@sha256:f190b7986690f344523691e1803de5f063c14166acae7aef3490eb5d9bd8d850
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/alloy@sha256:8ff0f67e59b303e40cc6b2fca3fcc3ceb362763813ad0565dbf71dc3e40b9a81
SPDX SBOMhttps://spdx.dev/Documentdhi.io/alloy@sha256:e165f45de028df6ca04f45c30bc5756730c2f168094d277c236d333f6f0a4423