Sign inSign up
Grafana Alloy

dhi.io/alloy

Grafana Alloy 1.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.20, 1.20-debian, 1.20-debian13, 1.20.1, 1.20.1-debian, 1.20.1-debian13

Index digest:

sha256:459ad2abc88e326cfd4cd8207dee04d119d4e2caa93958e879128b4dc6d48661

Manifest digest:

sha256:2176bd1dc400d77816927ca17a32f839830f8c01481b0bf54599436f9b7d9ec6

Size

99.06 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
2
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/alloy:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/alloy:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/alloy@sha256:be2559d4667446a10accd3cf582dcf765c10e9c27c98b2889938c29a5df050ae
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/alloy@sha256:c968156e6bb9eb75146a942a1cd04a33ae554c2b4fcc0b143dbd16d3b453858e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/alloy@sha256:41447079aa85597eddddf9d8f87f00edc0440a099a567c9b9dde0d90ede493ea
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/alloy@sha256:3f0201adcd7763c03c5eff38099f5e97d59cfe63e31e3bbeb50ff7b8ed48f3e0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/alloy@sha256:aa815f309392eddd9c7729f602b73eac1d33915218cf6d73b5cff7e12b539c86
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/alloy@sha256:a1144ff248b4c9213ca8bde8436007a76bc93989077afa4c26cb7afa3dfa80e6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/alloy@sha256:04ede5f230e7dc857ccf987a6669cece865e162f88670241d3c21bf3282dcdbf
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/alloy@sha256:b1582c3e176771b47808b89ece433318a00ce4284fbe233a092c7eed86b32bb5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/alloy@sha256:a226681e186f8537c14fba28852dcbe57fcc2b810db1c48b22a8b7dac553a05f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/alloy@sha256:c5a0de758c532bf5a96afbf95d8ad7d821dac4b0d56344f4c4bd11750938a395
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/alloy@sha256:1ff3ceebd13ca2357633c8e874eb4b5500a42af02778ebd496ae2354d80af1ba
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/alloy@sha256:6e7dbe46d65aafcd2b0de648ac9cdad7ee9ebb091885336975b12c5c8470ebc0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/alloy@sha256:9e3762fe7a37d00d98a25f525ef4ea736c37712b34b3f0384e3daa0d8f13944d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/alloy@sha256:9208d048eb987073f8cef743cbb8b91d9fd6f1318723d8a81e3eb915e2b2e9c6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/alloy@sha256:82e42ec34de5d7de50caa034a62b508d96c167cc868c7d4dca38763eb74cfd59