Sign inSign up
clamav

dhi.io/clamav

ClamAV 1.4.x (base)

CIS
linux/arm64
debian 13
Tags:

1.4-base, 1.4-debian-base, 1.4-debian13-base, 1.4.6-base, 1.4.6-debian-base, 1.4.6-debian13-base

Index digest:

sha256:282d332dc01b83a6237ea143db580ffe29d97bb1ccdcd8cc44ab6953a9981c62

Manifest digest:

sha256:3b0b7405f9f101f0bb5acfd56d3c8b31ac46777e8bb41dac32ba946d2cff8549

Size

34.41 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Aug 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clamav:1.4-base

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clamav:1.4-base --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clamav@sha256:904dce0f94a481200c538ce9cd297861154d8de4ade04ecb84b4c5d9cebb4b0f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clamav@sha256:9a0b9588f85a3ee172d8b86db4798b816bd38d80ffd1af69481f504a50087d6c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clamav@sha256:e0a3146a42604725dcb6f4ea31bfc902c529361013d1cb5c95d839fda9430b66
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clamav@sha256:1d76e791dae0be7228a4d5d55d0c5480357a4635653553a91c8267956b4be89e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clamav@sha256:6f44fcfc37450d0cbf4ffead7205de25d6888f63f408b5db46360c834f2da88b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clamav@sha256:df33a6ec61777762aac00cc7d08eb14e5563f4d551e9f28fbd9262c2c2fd5361
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clamav@sha256:7130ecd7c0e74366a1c8b696be59fbebd15549c5597581f95c9ea1730f983028
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clamav@sha256:7633e29dce6a603ee5a5575d56dd0caa3a355660cb281409a59c039184e6fccd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clamav@sha256:bf41ce33896860a5bf6c2452744b034de97d9d16d35831d9ef0b02db7abaf457
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clamav@sha256:af03ef7e8a69d013b3186a07a1a40af42c9c390db62460cbaae16c6237320c83
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clamav@sha256:c4ab402cade1e51398d9a8e407bc933173d8b5f118534ad77ed0d844b453ecef
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clamav@sha256:8b82bbfae7f05f7a394bea9ba003e36ea9667942ce950496295def4a11d7a811
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clamav@sha256:c9a3cc9d692936a7b05856b56a52cad2ef1faa366e50d38c648741859c6a3c39
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clamav@sha256:c611d3853e2f6f3378c03ec4b6a233d1d665d147150e0614783eda64a4f2f528
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clamav@sha256:82cc4701489d4f65d8e19e22e1a8201021f61a557cbd60927e38f2b7804dde99