Sign inSign up
Grafana Loki Canary

dhi.io/loki-canary

Loki Canary 2.9.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.9-debian-dev, 2.9-debian13-dev, 2.9-dev, 2.9.17-debian-dev, 2.9.17-debian13-dev, 2.9.17-dev

Index digest:

sha256:86ce8978a98b521070c12d33d1640ac4f68deab046443ed92759cf837291a801

Manifest digest:

sha256:7bd3e5e5fe21f0c4c43311f41d3323fc33f0acb161a7c2ec165ccb1b7606dc48

Size

32.43 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/loki-canary:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/loki-canary:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/loki-canary@sha256:0d5aede5e42295f3970d254ef360538752311e2d7970031eda89484d16736bd4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/loki-canary@sha256:ef695a195ab1c154e3b4fa5a4804381609668942a95ced9d610c6f06fba2cde8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/loki-canary@sha256:c08728fb091345115b2200ac34982068614912951c9571eda628ff9daf91e844
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/loki-canary@sha256:de199b1596e471a870e2ac8fecbe343ba1ee516cb7dc7c32571b65e10fefed99
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/loki-canary@sha256:a2a139b40574f18e8a7ed091ba26df88429b846e2accfc482a9710a13cdc2694
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/loki-canary@sha256:11bd8b3fc66eb59dfcd513ae439807118a530241b0a5c9d13271e0711ca67b43
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/loki-canary@sha256:8b7b86ade766c974e2186af674fbc5d81b6fdc3e1bc8c95508538a1397f6cb93
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/loki-canary@sha256:1700983fa977f0f9f3855adffbdadee5a62a7919f14e49fda5749cc4e2492683
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/loki-canary@sha256:73259cecd05db302135d9b2445d5b8df1b515ea0f690e4e1f5a709eaaad2687a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/loki-canary@sha256:bc5ae4f479ff8d13a93329ee9311728617b0e8765b008157a550895b6bf6663d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/loki-canary@sha256:eb63bb41290d107b79f3646cbd855d128925f343c7f606306ec9b1af9ebd0f90
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/loki-canary@sha256:d4655084ffbc07cf560d8818f3fd47dbeb9b89ea74de9e4e5752c3dc62011fe7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/loki-canary@sha256:023c9aa9d9925dbe98422f1884f63ae022b987f0124db75da77f84acddc91469
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/loki-canary@sha256:04e8f22243606776448c252c980e846fd576e79ed869d86d1f3f1ff15ba0c280
SPDX SBOMhttps://spdx.dev/Documentdhi.io/loki-canary@sha256:07efd496ba43d1771a992ce609eb840b24ad13ae8517720375da6bf8b98243f2