Sign inSign up
Grafana Alloy

dhi.io/alloy

Grafana Alloy 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.20-debian-fips-dev, 1.20-debian13-fips-dev, 1.20-fips-dev, 1.20.1-debian-fips-dev, 1.20.1-debian13-fips-dev, 1.20.1-fips-dev

Index digest:

sha256:e84040e41d5d74154fd05adfe3bf5c5fb9faed79bd90b9fa3820d572dfa13f32

Manifest digest:

sha256:a6dc36828bee8cc328ec6a6b86216aa42d679eb151a24770f8572644838b14fb

Size

118.53 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
2
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/alloy:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/alloy:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/alloy@sha256:41db120c4c4c19057c117ae56d70106f882a9df3b59fcd399be445c150713e3c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/alloy@sha256:66cadf9e8fda7359a233587a647ce96614f43e0fe7df072e436e39631b361382
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/alloy@sha256:8bc7048ad6a91bc1486a25b24303d318ec4a79c5d76d52d5b30f4a4342b8fba5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/alloy@sha256:c856cc2efbc370ded827ea092c5bad0162556a27954b921f5b3b3537a59a075c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/alloy@sha256:bed9b4a2f8608faa8ffbf0d94b6d1c2d328bc6a858c88deb2a8c73c2423832f9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/alloy@sha256:6d363a86686ea67b80ad4cb2c0827da619e385dc8b6208190b1b47743aaedf95
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/alloy@sha256:77d795315ef2b41ae2f2640b3821f2753e7fe3072032d9500e5ef1b326f0ce9d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/alloy@sha256:eadaff44734b969c5a633328d1b3a3be3aeb0e3652568f0f13b78c0eef168474
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/alloy@sha256:0d6d9bd007315b010fd040521a142b8272f0819c9e0263626e853b3334133727
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/alloy@sha256:3c6958e8bb6f450eb65179c159a73df2b5986c30c877d869f0ff266751e0eb13
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/alloy@sha256:abe33be3a1390d680ecbe6d2f8ecd3d4973686f5303943ca40a3e12e35545319
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/alloy@sha256:8ceede9645080651fa3c900b9173dd428b01015e2fe118b5313287c21d4f0216
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/alloy@sha256:59f6cf25d40b9dd7789df141542d82af1c6cfe7cb546253f024982e5521c3a87
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/alloy@sha256:9a87f3c256249df997c97a22b343843eb88552ed06ca1aa21f1a72b85fecced6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/alloy@sha256:e580f1cfec55ad0dea3aacc32584c8be56c48d16065710ac87a7d1650c2a4a82
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/alloy@sha256:70f7d51d60ee4cef0aa7746a7eb7eda6a236b76078c91e2617c749defb515085
SPDX SBOMhttps://spdx.dev/Documentdhi.io/alloy@sha256:b1455ca5293fa1e9040dc5b9b91b54b5e867c43ad2000751f3249afb9856f5d4