Sign inSign up
Grafana Alloy

dhi.io/alloy

Grafana Alloy 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.19-debian-fips-dev, 1.19-debian13-fips-dev, 1.19-fips-dev, 1.19.2-debian-fips-dev, 1.19.2-debian13-fips-dev, 1.19.2-fips-dev

Index digest:

sha256:8701de8f556bcc21ad119656ca8a9db36a356d548eeb691efe8437f32e3e9f96

Manifest digest:

sha256:6c25713c2b9a0de42a440dfb6a3f65d529c34288816111ca6d6c37abe5ce0038

Size

116.13 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/alloy:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/alloy:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/alloy@sha256:60316afe8a3aa7a68db1ea0e74ab248bb2615a80b3048ea10d35c885def7cb63
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/alloy@sha256:bc4028dd7622daccfead8fed6169c5d04ab095b8f35e15a0b639b9c8b1a7f768
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/alloy@sha256:d1db5ae5e0d92a9f82669f43555ac968e87ba0618dca59aaf13c419d66ccbcc3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/alloy@sha256:b6a603eb89f5eadc6c358330eda19239afec117c9ebe37b383ea486f9bf49560
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/alloy@sha256:8c6ff58e479c28efc3d9554604f90026e6ded55bf3ab6e9bedf68ff4499b8b79
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/alloy@sha256:4fb643335871435409e9d8e662e7a512a8886e0c902689c0c20ddfa7cc40645b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/alloy@sha256:f6c3e6ea08d7441daa4999c8e759dbb863192bf99b42a4110ad674b142bee612
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/alloy@sha256:58749174395f5553eeb968a321931289200fd6253826ec39d8427068cb997041
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/alloy@sha256:f51e09b5ee5db354b2b1f25d1c57608272d97a3fcf80bac0668f1d5d2de08f50
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/alloy@sha256:0fa7ceca4699234dfb9a22e3146d91cfa23bf49db8bae95c8ef0f334ac5db15b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/alloy@sha256:716cab088c3e0ffd6094ad696f62dda88c71b27886c0106229ba39c1820c8480
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/alloy@sha256:fcd53848067fac3d75184057228d01d6c42b8ccca5f50c958fea7a11311665f4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/alloy@sha256:01a398de8208dd00a91305356ac90d05f4c574c532c584b8e0c9d9f95d8a6a45
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/alloy@sha256:5d87d18ebb4b5c2a3c2bd450aa666977ee352972272717df1c138f15496d57f4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/alloy@sha256:2fc44a044ca3e0cd32476f1b88e3392ad7028aa0a3f22f68741fd9b777f380f0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/alloy@sha256:3276ece9ed87d4f4b059f21580d8eaca9c048867d484805669e034cf2f51a6a2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/alloy@sha256:fa6358add8b93555b5f0b0ac1e62272778ab80f438d118fd2095c44643127982