Sign inSign up
Grafana Alloy

dhi.io/alloy

Grafana Alloy 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.19-debian-fips-dev, 1.19-debian13-fips-dev, 1.19-fips-dev, 1.19.2-debian-fips-dev, 1.19.2-debian13-fips-dev, 1.19.2-fips-dev

Index digest:

sha256:937d34cdf28d7101ed105ea574611804dd3e5da44789fa7bc456677f0cea1ff8

Manifest digest:

sha256:df69743ad50cdb2fec5e71aa988f65b6d53825e066c85ecde26a6dc68654622b

Size

116.13 MB

Last pushed

53 minutes ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/alloy:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/alloy:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/alloy@sha256:5770c832ea1b028b074edb063576852ecfe7fe658cd438ed607d775d0e2b45c7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/alloy@sha256:ae933033385333793c73bd8feb779c8c4e7c0dd8566a2b51f4f413c8a42dad5e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/alloy@sha256:5f176ccc5da1bd4c079ffd86d81b1a531b63bb045817beb0bd45360d79a162e7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/alloy@sha256:d455856fd4e0cd2eeda0e805129e40a9bd22891974535b4a6d6f0b1207295f66
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/alloy@sha256:9eaa17945355dcc55e6aaac0ee440141801e4092b3ee3540fd522beafe14bfa2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/alloy@sha256:fbdf61d792bfb6202113b2c7922379512b2ce934c25cf9b24287aab0c641038c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/alloy@sha256:a932ee40da0f051b45495c9038903e0a660c97993703b7a8e3e0cd234acba610
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/alloy@sha256:5864510a23402a421108b7ba114368f1d2f93ebc8a1cc272e09537a934b2eb9e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/alloy@sha256:6faa95dbd6b15bc8ed7e3f723d5317d1c1aa70436039917b1706c2685c93101f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/alloy@sha256:25d6a6b4534f82998c57fa7a62f10d946640feb0d32c6652d0cc62320eb27fd7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/alloy@sha256:4916469b2b7e33c3f90c9eac89c410ee8dd202716efe76e65ee50ef7e4897733
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/alloy@sha256:8c74ccc9c006d8a711365fcb8ba2cab302aa57197f6ed6c5ac6a852486073960
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/alloy@sha256:780dad58426fb2962fdb2053fdd97b0401d28a6bba5d504d6e8dba6e28163c49
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/alloy@sha256:4a306efdecb9118798902fc2a5fd7229a25b55cff4ce9e7818692b02d9725131
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/alloy@sha256:387e43cd7a8415321e2500ccb8970b5c9e787af59ea2de0192c597144b0db77b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/alloy@sha256:3ca9b4d2c506b5a7811520abc3e5e5c17074a381ae5f865151dec8272ee1e00c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/alloy@sha256:8ac5e4c185e86ed6cca77f50990bfe41f566e41a0a02facde4f93d87444d6daa