Sign inSign up
Grafana Loki

dhi.io/loki

Loki 3.7.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.7-debian-fips, 3.7-debian13-fips, 3.7-fips, 3.7.7-debian-fips, 3.7.7-debian13-fips, 3.7.7-fips

Index digest:

sha256:4c092a53648752816dfde6824c7e1c7876e294dc0e4d996f27f692155dbbd660

Manifest digest:

sha256:e66bed3aff8833c808f18d473ea34eadc9de804d409b120e1dba54ccaf2fc335

Size

49.41 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/loki:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/loki:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/loki@sha256:caeb14fc3f0a99a4682e953411e9ae20ba0a71c56d28e70de7da50fb60f7baed
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/loki@sha256:0e158bba459cdabce9812e84a4d3dcabf7452545d16f96fc6baba4e7a9f616e0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/loki@sha256:4ae60e78f4654c907af9d93c1d1cbfe1f9c449765b169b46a509c97c6bce8a84
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/loki@sha256:1931e78d092f5fa330d415d8dd25b1a200c984aaa45752a2451cf950bc844a85
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/loki@sha256:7cfcfea8d9f14b9197502aca148896a58fea0f51ba258fd3276f86ba02016ec7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/loki@sha256:302c8ae5196730fa13be4e5ca276155c9d945a7415b6d49d5b1abfb3e68494f2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/loki@sha256:3dc0074502d472370f6e02ce59c1a7701ab9aa5f8ba8016bd1f6df7da91b3e7c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/loki@sha256:a0eece0666c9d57df1336366f4daf68617138d8fe81fd259390b0b87fd4f456b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/loki@sha256:04da1951262073bec342fc92a4b82c0fe424c6522e6c771935a9d9341516e2e3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/loki@sha256:0de12e7d2655fe0f287391243c2529343636ce726fd5254145f4e7ffc589678e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/loki@sha256:860b08aade68095ce6ce00f57c66c8f0951eacd4d853354428ebff70da0b70a0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/loki@sha256:5eec3a82249a80705cfcab96f2cdd46f7f151f0d4b868492ddc08b00d6b99b49
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/loki@sha256:adcdbddd57de59d64f41cb38dd6be6c1bdce6f5e994d50cfc47231e4f59c0151
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/loki@sha256:23ef3df6d97f0cffe4497a2247e1c8cdd07eff5da7b1b09b434853ad6c04bd3b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/loki@sha256:d17e35505bbde2c36545f538f99720a7620052f199677ddeb82d0436871c400f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/loki@sha256:c588817660973fdcfd3d886357ebd0107d7e20e583d7c9130a5463faab1eb029
SPDX SBOMhttps://spdx.dev/Documentdhi.io/loki@sha256:2d0631be8f8d94b969051e73f471047fec074307af125c4ae2f0d2ce0d53e23a