Sign inSign up
Grafana Alloy

dhi.io/alloy

Grafana Alloy 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.20-debian-dev, 1.20-debian13-dev, 1.20-dev, 1.20.1-debian-dev, 1.20.1-debian13-dev, 1.20.1-dev

Index digest:

sha256:b5d6b9bf4c89d2274d9354abd9f261bbe9ad0781dba0a03821d4238b0c953887

Manifest digest:

sha256:aa4247a8a719e4f77ca673f4dfb5864c6a52c1edd34936cc64fb4945af499418

Size

117.77 MB

Last pushed

8 hours ago

Vulnerabilities

2
8
2
1
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/alloy:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/alloy:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/alloy@sha256:e2218be3d2feda1c97de2212bbc76e24997027b3b8cca7aed855aecfca580f49
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/alloy@sha256:33c1e1073d835e8249e0476f27c695a65bd322bfa9ff615b8ccce28d0dc5ac9d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/alloy@sha256:f005852c8feb1ec5407e3799299d4c6af99293fa3f7bf4bd367ad064031bbc09
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/alloy@sha256:326dc20437420c8d95806afeea0516e3882ecf2241b45524bee30af2bc7ec4dd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/alloy@sha256:b1b520dd3c3547c71293a9b1a7e8427aeaad18c2d684fdfa53e92737eab49299
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/alloy@sha256:da5cb470a1c927caa410ae2e8f1bdd80a840c671f270007142d5dd2f5b9162a3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/alloy@sha256:c4e17c999eef2a431df97c78873426ced93bce097d362c96c567e49fb8f5226b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/alloy@sha256:b2e734778515c21dda07944ff57930a9b75672af06ab358a4159e012dfa50508
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/alloy@sha256:cd4b6ce4c4c66aa03372c82d3fb566770c448340ef6b0fbb4039d2308b784ec1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/alloy@sha256:2bc0dd0d993f2fcf33cfc32f47a252abd8393a62f9d208e6c7d2055fb68a10e6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/alloy@sha256:30dd98677dd4365fad57be37ffcdd0c4f571461b15d47496ea01cce709952adb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/alloy@sha256:03588e99e73b6fd148008c6e3b8d1cec077606a2afd6bb694834e63e034287f3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/alloy@sha256:abd5a7795750317fd8c2cc87e47739aab0153c3ef4ac3be21322d3b00db5096a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/alloy@sha256:d18d58cd067a65212aaa8d6d03bf76d542ae38023f2b7471f5bd76c10202d71b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/alloy@sha256:1775685c1e663bb96de9d0e6dbca7c1e81c67cee1dfba612f7dcd3ed926689db