dhi.io/loki
2-debian-fips, 2-debian13-fips, 2-fips, 2.9-debian-fips, 2.9-debian13-fips, 2.9-fips, 2.9.17-debian-fips, 2.9.17-debian13-fips, 2.9.17-fips
sha256:068099556c6cbff7f04f74029f6cf6d14bd9241fdd3151e086b5f9fc4a5ddb38
Manifest digest:sha256:d181d5a13562d2670b14ff78a56441c6aad086ce19f9378d91e336129af74905
Size
31.69 MB
Last pushed
1 hour ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/loki:2-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/loki:2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/loki@sha256:a8bc527193810aed69fe2aaaff2620070a7b239972a63b23b43b2a2178d6cbaf |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/loki@sha256:d343665b2686f38c73ae5c600ff4e73dc4b7dc19e241480cd08cf774a4656a5c |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/loki@sha256:28fc3926d888e7886f06659de9a4c55afdcc3a8ed0bd94c8acf8e2b079c20e4e |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/loki@sha256:564b6fcb0822ea5b2636061e9097320efa5ba6075e6e40ea31f71afdf23ac540 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/loki@sha256:87013224122a67c28a4774b4ac88f425d300169afea979bcd528b9fce302af98 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/loki@sha256:beea7355e1ca381f465ab395c1362235cd7d65d351750addf5471cc5b7975d4e |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/loki@sha256:dadbebf65779051e5cb13132a86809728974baf443b24c846142cf2ad816d354 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/loki@sha256:b3c61ce3e9b8600b53c92c751c7914c10e3502f1952adda3856dbb9bfd1c598d |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/loki@sha256:02d74caa0d6bb5befff843e562b90b1d8da3eb0b110d6b95213e5b981dad73e0 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/loki@sha256:180a4ecda680fec453f9a4657e51c9bddfce38b428a718324bb9082adb135394 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/loki@sha256:9ef2f3a15d4162f3d1dec81204edb9a4c2648dcc32e7d59e97580e47493a6824 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/loki@sha256:5e73d3291c617206787f581551b08bff677e22415d867570b35a267db6535ee9 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/loki@sha256:762269b09fc7880373c550981cdfe08900b1df63d326234c88d3bdd06eed067f |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/loki@sha256:9646f1adea7becf786ffb4703effa9d1d2d4cd75d49df867e64d779fe9e1f93e |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/loki@sha256:047ac84f7dfeec97bf3c088423713c2e52bc7287479aff7c95a749d2aee055a5 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/loki@sha256:cc717dd0c3001552a0eee20f08cd3aac12efeba41b4292918234e13f2c80b1a8 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/loki@sha256:ee03f430cbcbf6c6fd2f2123378ebac40f0752508ea1ff0d62763e415efbee80 |