Sign inSign up
clamav

dhi.io/clamav

ClamAV 1.4.x (base)

CIS
linux/amd64
debian 13
Tags:

1.4-base, 1.4-debian-base, 1.4-debian13-base, 1.4.6-base, 1.4.6-debian-base, 1.4.6-debian13-base

Index digest:

sha256:aa47014ace9e1a4ee7ec0fb5d003d6d72400b480f025ea0d12835140c172879d

Manifest digest:

sha256:a68839e832c39ba190ba7aafb8bf6dcf531a468fd4315334a43cca62bd9a77c1

Size

36.06 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Aug 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clamav:1.4-base

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clamav:1.4-base --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clamav@sha256:35e18f7be52715ffcb3f2ec40cefabf5b48e53a5725d089bb2d250cf6de6a2ce
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clamav@sha256:66b06129709efc5d154921b189afcd488821a0f368ca30de6be36addcfe07d73
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clamav@sha256:c3c21affe5bb919e97a874deb185fa548aeb57a3d67d134e5327a6b132f156a4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clamav@sha256:421fda380fe72e6fe5e84f8fab13725cdad6b9b2ffad9f488a7750ca6345c345
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clamav@sha256:c9563e6ceda069cbff597cc321b1845bdb6409d00d58faf5e985f140d6709bc8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clamav@sha256:e26c3eb0fa96c8d99af8a5275849ba3446765d5ea3067bf2f42cf33d8d2ed046
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clamav@sha256:7614f1a8db95049eb799772bc09d0b9e3c92b524a395c9273c7d5e3c69a7be65
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clamav@sha256:b77d8c0d0908e598a52a6a1f4ee866aa4591f60e1ae567a7c3d35f5dc4848a9c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clamav@sha256:1e326f92fd4d6a3e08e6e6a6d8940de60ab514acaf0714f05fe0ccdb28230ab5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clamav@sha256:a53008001fc4211e5bfd3b86ee419e914e6cae94ebd31951d4caaa5900d52a0d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clamav@sha256:ad25d78bdc7591aa65e39aad27896f868da989b48c8f0a92372b0f8d035b3c22
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clamav@sha256:38a3646df906ac024ca595a5e0269e54ae6f76a8b308056dece96b87ad7b12f8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clamav@sha256:00f00b7aaef17d3fe1f0224e78d184204f164527fc5f0abadd734a0a67203efc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clamav@sha256:699974c3577563ef257f11221b525082a092e0dccfc1c3fc0e0b9f52784e04c9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clamav@sha256:fe497491e23994b3a846f492bc626450b367ea4428b43a6fc1de45c39d8108d1