Sign inSign up
Grafana Beyla

dhi.io/beyla

Grafana Beyla 2.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

2-alpine-dev, 2-alpine3.24-dev, 2.5-alpine-dev, 2.5-alpine3.24-dev, 2.5.8-alpine-dev, 2.5.8-alpine3.24-dev

Index digest:

sha256:032027a7fd3f888e2fc8999eecee3fc98f8a5b53ceaec5d10e91085f5a71842b

Manifest digest:

sha256:3cfaf349f682caf79a2979c50d995d29fd3ce82b218a1de5654772e34e74550f

Size

57.21 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/beyla:2-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/beyla:2-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/beyla@sha256:d21341be67123c3c87fc757ab53c4974d574b2a994e582bc0f8e0c4453c4b8fd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/beyla@sha256:f6eaa08c193cc772f17a4723825e6b2de4e04e23396b4b7388f1b724d17ab8ba
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/beyla@sha256:454dcf02253ce467f5f6b112ac79ba08d4071b00b05f22c507f93ea2623573fa
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/beyla@sha256:7fc03edd9a62bbc674d363340f62adfee86aa8a9eacefff309a9ec5d352dc39b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/beyla@sha256:2f950d4481f436334df3a40bd0aec9d3c6438479fc00d0efd436e3031234e89e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/beyla@sha256:563981004f32a9bb8252a67b3f35139735c5ed7db0d8d1ddc66f873c0523e135
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/beyla@sha256:37dfb239176e1cd309d57454eeec5cb6beeb18e6d93cb01e1a971dc15ad6d81d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/beyla@sha256:c726b1afae6287efcf4a75413ddea961f24422f6d423a26816153170cfa8f640
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/beyla@sha256:37d422381c2903de710f288e79dcac12e95568615a53a61627a56dd19c96bc26
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/beyla@sha256:6c3b939497b8b1e758baf15a23ae768d8587ae35173bf81aa87a33cad473d06c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/beyla@sha256:ecb952b247319f4226b92a7af5743eb3b6f1450925f601ffdf53209fa2965f89
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/beyla@sha256:1c1ef1fe7f688ff8a83697c7072ebdecd1f776d2896551f5fcf5ff17d3820c68
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/beyla@sha256:432027deb2e2cdd84a659a1877e9e88d0646846402060a62973c2cb38a893cb6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/beyla@sha256:23a4ae50048adc52322cc5fd93d4569798ca69d4811a4cd626dfdfc4141ed4ad
SPDX SBOMhttps://spdx.dev/Documentdhi.io/beyla@sha256:447d08ffeac255d1de7fe4367f0c43a5755c210c33e792c8e259531b7c2a190c