Sign inSign up
clamav

dhi.io/clamav

ClamAV 1.4.x

CIS
linux/amd64
debian 13
Tags:

1.4, 1.4-debian, 1.4-debian13, 1.4.6, 1.4.6-debian, 1.4.6-debian13

Index digest:

sha256:4580bfc71afdcc923ba539fc0b2c4c1c492a10d5abd481d1cd9e332380c79416

Manifest digest:

sha256:2592fdcd2c9266cb774724e0d6bab8315df66b4a278748fa705f9746159d867b

Size

143.61 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Aug 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clamav:1.4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clamav:1.4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clamav@sha256:616e541ded52c526186e2e7638803cf2d90e60b8210c8b7c648e51ad418c11df
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clamav@sha256:7430240c4e86f18c8b916781bff3ae376254395844ebc046fd8cd5ff02d23be0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clamav@sha256:b4857cee3d92211f4eba57e6e8d6240c8aceb33692e8730f964f6bf5dbf267fe
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clamav@sha256:c92345ea0697fac9297e852e46a8b7b2e24ea3d27b663623b1b20c2af54ff760
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clamav@sha256:a003c02ac5f7a08bb8f3766a3befc56b8881c6ca83a086809de53b7312998382
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clamav@sha256:70df01b230eb92cf54301236908dc593f49b6f7d285337c9901cf771544439bb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clamav@sha256:dae4edbaf85282330545a0fceba8c6da1e175ff578897aea4357273279cc6168
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clamav@sha256:8a1266a88da48a7431b87b775256d78efe6924e6839a321c327a6e986e8a2585
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clamav@sha256:26e2c4abb8fe8090e35748fb73b9eb4eec456349cf39ecabf8de87e8f0cbb540
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clamav@sha256:2e7ecbaf61855df2023a57a0aae5308a780d73f35db47e1bc9b408a5ad2a4f37
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clamav@sha256:b4c85e1da361093945c9989dc99c95475c9cc857b33eaeac38ee3a04ab3852bb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clamav@sha256:03215bf26f638ea274b6e64cfd6180eefe9d14cf64b38cd4632828c525bd0a3d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clamav@sha256:67bdc96d8cf7144b7f2f9d7ebd031cc641ff6e98bbae25775990d85f32b330bd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clamav@sha256:3e65cc3d09f6261cc1f24f8f59db6b2f138e78905905b5ebd3d279238402dd47
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clamav@sha256:e5d46f89a28a8041578bcfbfe4877fa5abc57f9b96c0ce16261e0f10ab24efae