Sign inSign up
Grafana Loki

dhi.io/loki

Loki 3.6.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.6-debian-fips, 3.6-debian13-fips, 3.6-fips, 3.6.17-debian-fips, 3.6.17-debian13-fips, 3.6.17-fips

Index digest:

sha256:cef26d0556b41fa6c77879a6357a25d67e105a0ce42e702058bd44a8af83f778

Manifest digest:

sha256:1af9567e7a3d81ead6762338a500f845fa4d226e43585fbb7d0f953f7f3bc56d

Size

45.53 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/loki:3.6-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/loki:3.6-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/loki@sha256:3a0bc1204c389127ac931f81168cde5718eed129f2f09b39cb12015cb3e8e53b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/loki@sha256:92eb17944ca199991c5caa8681b69e277bccb0514a08540c54084cdfefbd93db
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/loki@sha256:c52f781baeabe40dfc2a8d994f1302b39ac9d173f2b70a4994f70d3586912c31
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/loki@sha256:f33ab81b43a6006af56be2b4a58b612cda63ab72b58a1d771fd580e16c15af12
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/loki@sha256:aded7d4a6fe3460785640af4aa7c66f20ceb0405f7232cffea72b42d93505703
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/loki@sha256:50c10b90b310341709d6f260f68941bf255b75c3f5dc83b68e001000f004c01c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/loki@sha256:85d82239dd2e160b22afacf17ee856ac3644bc6fe37f16699164b5f5e134e956
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/loki@sha256:8c3bb2c6eda153dd133c2161e2490fb836f021ee473d996076d4c9a685b60b13
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/loki@sha256:05fb31d73a712b3e0a39393725419d42712f13ea8d1edbda6792830a7c72f83b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/loki@sha256:cefbfd1c6e0e5ed0ff84ad857086b77c5f94e7add5bee52c7ed6d9a20ad5f8b1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/loki@sha256:4ac27f32b052a86a93f22b9f8a81895792f464cac6b5b0a7f155b82175cffa03
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/loki@sha256:85333aedd3331a63432a1f3f1525b08e4e417627b707375cf8c5252dfa9b01e1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/loki@sha256:7ee14bb9d1e9a3d0240cbd8bb320256d1f5790b5a0b0035c07e7475693aceafa
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/loki@sha256:bb021d52b8fd2c8efe9e98f469527b8896556a37a80a01bcee4bb762b2d7629e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/loki@sha256:35efd4f1729b1e2f1b679ebd2e33a6f3be0df0de8383cdb4162f398068d5b02e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/loki@sha256:bb2d41970f4831c3ae737433a63956f17b64921497880ad75b400a3819aefc8e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/loki@sha256:78f99fcfec836ad7897a7579d1878a7debb6b1445571d5a3a1c8378048b7fbf3