Sign inSign up
Grafana Alloy

dhi.io/alloy

Grafana Alloy 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.19-debian-fips-dev, 1.19-debian13-fips-dev, 1.19-fips-dev, 1.19.2-debian-fips-dev, 1.19.2-debian13-fips-dev, 1.19.2-fips-dev

Index digest:

sha256:a51aafd24da8831af4a7ad4cb804f041862539e75a5d835bb936ce22ef6091e3

Manifest digest:

sha256:41d8e4193972a43d1cc2485d8779b1ef4de01f8bec2776b79a792506cdbe5a47

Size

116.13 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/alloy:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/alloy:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/alloy@sha256:5c57c4d461953ebc0ef6fe48ea6e717cd5efabeadcccc4e69ce49001833824ef
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/alloy@sha256:9ceaccf54c2d3e5bcb3dc6908f451b3932537b92b93b3c4abcc564936be866f9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/alloy@sha256:0bffa145622d61d9f33ba3202ddb29909ab8c5b92cf55f6b2704aee16acacf3d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/alloy@sha256:f7dbe6dad0b34343bbc623440355b4d6e2c8bc59c9fdcab7104e2f30801fb811
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/alloy@sha256:0a34d485f52f150664d0ebc4648982a14419feb502b7f872c0e1ae2b01ebd990
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/alloy@sha256:1beac75376218b90973fce71b51ef751111706746ec150917f3a37e22d632e9d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/alloy@sha256:3ed8036459ecc1490d9713815699871a9449b2a616e9afc4c5c963248e67e449
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/alloy@sha256:431aa6d5ad6fdff7b4d9aa4e3c88952855e67449fb936e0614964b2a50a8cd3c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/alloy@sha256:5d31c9e79420e09ea729c47481dc21e3eb48aedec7e8affe2c1c8dd238371c3c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/alloy@sha256:87c35022a294b8cad9bc1356b037ec83c983fe5f1c00082c30815ae63cb05b43
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/alloy@sha256:e3b2c84e43079d3a0f94ced5b9e54f61acb8aadaa6ec352d77d6e855fd43d4aa
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/alloy@sha256:8d12d0d8f297a5638972f33823e89ba1126df6157d2dbd31fdd9f91d89e348ba
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/alloy@sha256:3af0701bc174f8fc5652e1422de30766ff63e6bfc65ae5b326633fa608596b1d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/alloy@sha256:43ea35c896fbd42449c1276d818171bb641bcf981062c47b6f60c0ec13be30fd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/alloy@sha256:b93b714c03835ae327d75e814fd8eee376a2ff40b607ade501e8732793588a6c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/alloy@sha256:05154f71d1d6dc4493ee5eebdbbd51e2cc69f9fe737820f0827399e61a61ea23
SPDX SBOMhttps://spdx.dev/Documentdhi.io/alloy@sha256:411f517bcee4d0b5a359befeb474a61d81dd5d2adb622a052fd566fd12c6b448