dhi.io/alloy
1-debian-dev, 1-debian13-dev, 1-dev, 1.20-debian-dev, 1.20-debian13-dev, 1.20-dev, 1.20.1-debian-dev, 1.20.1-debian13-dev, 1.20.1-dev
sha256:b5d6b9bf4c89d2274d9354abd9f261bbe9ad0781dba0a03821d4238b0c953887
Manifest digest:sha256:aa4247a8a719e4f77ca673f4dfb5864c6a52c1edd34936cc64fb4945af499418
Size
117.77 MB
Last pushed
8 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/alloy:1-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/alloy:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/alloy@sha256:e2218be3d2feda1c97de2212bbc76e24997027b3b8cca7aed855aecfca580f49 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/alloy@sha256:33c1e1073d835e8249e0476f27c695a65bd322bfa9ff615b8ccce28d0dc5ac9d |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/alloy@sha256:f005852c8feb1ec5407e3799299d4c6af99293fa3f7bf4bd367ad064031bbc09 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/alloy@sha256:326dc20437420c8d95806afeea0516e3882ecf2241b45524bee30af2bc7ec4dd |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/alloy@sha256:b1b520dd3c3547c71293a9b1a7e8427aeaad18c2d684fdfa53e92737eab49299 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/alloy@sha256:da5cb470a1c927caa410ae2e8f1bdd80a840c671f270007142d5dd2f5b9162a3 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/alloy@sha256:c4e17c999eef2a431df97c78873426ced93bce097d362c96c567e49fb8f5226b |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/alloy@sha256:b2e734778515c21dda07944ff57930a9b75672af06ab358a4159e012dfa50508 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/alloy@sha256:cd4b6ce4c4c66aa03372c82d3fb566770c448340ef6b0fbb4039d2308b784ec1 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/alloy@sha256:2bc0dd0d993f2fcf33cfc32f47a252abd8393a62f9d208e6c7d2055fb68a10e6 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/alloy@sha256:30dd98677dd4365fad57be37ffcdd0c4f571461b15d47496ea01cce709952adb |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/alloy@sha256:03588e99e73b6fd148008c6e3b8d1cec077606a2afd6bb694834e63e034287f3 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/alloy@sha256:abd5a7795750317fd8c2cc87e47739aab0153c3ef4ac3be21322d3b00db5096a |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/alloy@sha256:d18d58cd067a65212aaa8d6d03bf76d542ae38023f2b7471f5bd76c10202d71b |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/alloy@sha256:1775685c1e663bb96de9d0e6dbca7c1e81c67cee1dfba612f7dcd3ed926689db |