Sign inSign up
Grafana Alloy

dhi.io/alloy

Grafana Alloy 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.20-debian-dev, 1.20-debian13-dev, 1.20-dev, 1.20.1-debian-dev, 1.20.1-debian13-dev, 1.20.1-dev

Index digest:

sha256:9bd8f37d86b2244e1cae58b40a0fb33fab7157614aeb7170d5c13a3a7c587483

Manifest digest:

sha256:42b8a0ea6760e25528157496f2ed35da196a098ba0f9ec77f69e3683db28d997

Size

117.75 MB

Last pushed

1 day ago

Vulnerabilities

0
0
2
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/alloy:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/alloy:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/alloy@sha256:18c5d19a98264efd1a82dd038ea1211d821bcc0c1410ead00ff096b69aa4f067
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/alloy@sha256:ad983d648e422321b4685b4a2451c446cf64438ccec49b3907cc463bbe8fae66
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/alloy@sha256:77f3c125b98c92d1a5cc1dcd3506513c10608cd7682ba2ebb463ba2b46877e7f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/alloy@sha256:c316ff3289937bdd002b4d6cd9fce043648485cffef4deb380e504e6236c98b0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/alloy@sha256:9a6f65f9ea2f7b6f383c9a0fc6af1587f620d9496221731f7555c595efd819c2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/alloy@sha256:3b9d588f7f3b5f9f038c84a676185a977163793255123f421ae0e13f1cdc98cb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/alloy@sha256:1f152c34f83590b51c231a91e1e88af0796e022b4f88c21f435451f1a6f2f7b1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/alloy@sha256:f6b93296f91351d7cac09ab63a9d6bf14595f15e99a6a9e5958dcb7b061bf5a8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/alloy@sha256:98fa3a9da20ed7a3874bb31ef8ce338384d2556ce2af2185da0e89ec53bcd57a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/alloy@sha256:431c462e26382e41b364a1a8af9de956056f70f7c269ba50beb1b906686fd55e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/alloy@sha256:2219d2e50c6d2cfb5ab47c37af0b47bfdc873fa48bec89d5c060e554406fa435
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/alloy@sha256:974785fefd1528e6ea620e1b583ad6c0aa5a9186e50d7022ee061597e1cea06c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/alloy@sha256:4644b4aa93a79f3a599539b2bc08a0048c4a4b6a2497393ead79eaafdc1d523a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/alloy@sha256:b1ff89c4f9d0e7f557937bab6d633c47aa863174f8d4f4822e90066f05f43933
SPDX SBOMhttps://spdx.dev/Documentdhi.io/alloy@sha256:565668a555b6067b845b46e2fcfefc249274e93aa8c8fd42618a89d525a9739b