Sign inSign up
clamav

dhi.io/clamav

ClamAV 1.4.x (base)

CIS
linux/amd64
debian 13
Tags:

1.4-base, 1.4-debian-base, 1.4-debian13-base, 1.4.6-base, 1.4.6-debian-base, 1.4.6-debian13-base

Index digest:

sha256:06c59766191f3f2fb80bbd41084b29334219c52e6bca4ef72606b78966f2e6f7

Manifest digest:

sha256:3b9fd02257ad58cf3e87eb337a6027e37576563c1882d17094216e4436843d2c

Size

36.06 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Aug 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clamav:1.4-base

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clamav:1.4-base --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clamav@sha256:54ce36a20c4737bcc0be87bcbfef3eddd4cba1b07e7b4ff8401721b87530e988
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clamav@sha256:0251eaa4f3df95d439fbf408364943113db647f6aadb8cfae2788590552728ea
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clamav@sha256:a3fdef090c6d8fc9bead69b97dffebcd5a669d1fdfc173797336589a09f58881
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clamav@sha256:c2db739abde03f89d5b9f35f9fcaf8f4530e255e73799c46b088863cff0d9dec
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clamav@sha256:df9c136dfb72bb6ea1a7e73b535464022082ad643f5415057988c456bda03af2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clamav@sha256:cbeb5ebfc96548ad3a03c47488cbdd6ca1f8594e2e0a3e692b24e0d0e8b098e3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clamav@sha256:bb7fff47bf25e36ba18e58fc1a1be8a13d02dec6f972007e339661faa3972db1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clamav@sha256:518ff1f5f3a27c12f8a10b036e2ef8af75b0aeb4eedb49823832c134965e37b1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clamav@sha256:bab07d58ea28244fe659af24a7d4e90d5aa953eed4653ff6c9ab1945584fae30
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clamav@sha256:02fa7b2ccb4303350155bb7bc014138e10e5a43298fc58ff7a929e6736099762
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clamav@sha256:a7fc53a570838f1b88b2bfb4eae15c28bd1244165f5d8d894e9d50720e995c9b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clamav@sha256:6893caa60ca3fa152238f9f2e4ba157271af115b0e9c847a3e6f4b76e16e393f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clamav@sha256:0fb44cb29650a8d84a37c97de9ef916a21bffaf3e06a39ac5c1b4fa61c672fb2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clamav@sha256:fac8c50f7a041b9166a67e40b0d44b0da13db6c92029a09190daa36756d314d4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clamav@sha256:c98d45b06f7c8643faba436b1f7d3b3dce7dd4c8e7f678fe032de084d3d7ac34