dhi.io/alloy
1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.19-debian-fips-dev, 1.19-debian13-fips-dev, 1.19-fips-dev, 1.19.2-debian-fips-dev, 1.19.2-debian13-fips-dev, 1.19.2-fips-dev
sha256:8701de8f556bcc21ad119656ca8a9db36a356d548eeb691efe8437f32e3e9f96
Manifest digest:sha256:6c25713c2b9a0de42a440dfb6a3f65d529c34288816111ca6d6c37abe5ce0038
Size
116.13 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/alloy:1-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/alloy:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/alloy@sha256:60316afe8a3aa7a68db1ea0e74ab248bb2615a80b3048ea10d35c885def7cb63 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/alloy@sha256:bc4028dd7622daccfead8fed6169c5d04ab095b8f35e15a0b639b9c8b1a7f768 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/alloy@sha256:d1db5ae5e0d92a9f82669f43555ac968e87ba0618dca59aaf13c419d66ccbcc3 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/alloy@sha256:b6a603eb89f5eadc6c358330eda19239afec117c9ebe37b383ea486f9bf49560 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/alloy@sha256:8c6ff58e479c28efc3d9554604f90026e6ded55bf3ab6e9bedf68ff4499b8b79 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/alloy@sha256:4fb643335871435409e9d8e662e7a512a8886e0c902689c0c20ddfa7cc40645b |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/alloy@sha256:f6c3e6ea08d7441daa4999c8e759dbb863192bf99b42a4110ad674b142bee612 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/alloy@sha256:58749174395f5553eeb968a321931289200fd6253826ec39d8427068cb997041 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/alloy@sha256:f51e09b5ee5db354b2b1f25d1c57608272d97a3fcf80bac0668f1d5d2de08f50 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/alloy@sha256:0fa7ceca4699234dfb9a22e3146d91cfa23bf49db8bae95c8ef0f334ac5db15b |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/alloy@sha256:716cab088c3e0ffd6094ad696f62dda88c71b27886c0106229ba39c1820c8480 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/alloy@sha256:fcd53848067fac3d75184057228d01d6c42b8ccca5f50c958fea7a11311665f4 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/alloy@sha256:01a398de8208dd00a91305356ac90d05f4c574c532c584b8e0c9d9f95d8a6a45 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/alloy@sha256:5d87d18ebb4b5c2a3c2bd450aa666977ee352972272717df1c138f15496d57f4 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/alloy@sha256:2fc44a044ca3e0cd32476f1b88e3392ad7028aa0a3f22f68741fd9b777f380f0 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/alloy@sha256:3276ece9ed87d4f4b059f21580d8eaca9c048867d484805669e034cf2f51a6a2 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/alloy@sha256:fa6358add8b93555b5f0b0ac1e62272778ab80f438d118fd2095c44643127982 |