Sign inSign up
clamav

dhi.io/clamav

ClamAV 1.4.x

CIS
linux/amd64
debian 13
Tags:

1.4, 1.4-debian, 1.4-debian13, 1.4.6, 1.4.6-debian, 1.4.6-debian13

Index digest:

sha256:40274ad0f3e0e258fd50811fb3b8e9cfe5b7a0fc7e6be80d85a60efec20abc40

Manifest digest:

sha256:9519a631f526a8e21eae325d6b0bcc9d1a4d341bda1132389272f0dd4b603908

Size

143.61 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Aug 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clamav:1.4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clamav:1.4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clamav@sha256:764bf92a85db2d1ee34bce0bc79a2b54e6b96d3551ee643bbd9a6857b4ca3c10
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clamav@sha256:e76fce4e003d55fbd5736cd8f889357cd398c3cf83901abab192902447c0f210
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clamav@sha256:c61583473e6ba641a88f1e3ca522e181d52bc2942fce3db2a0fcf620868627b9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clamav@sha256:42355efd54793f0539b14989a704aa19143d5c0cc5ef1905d5b752644b952f48
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clamav@sha256:001c3d9e41d1897e477e4958d44c100b2cfdd0800d23bd704eace1370dd557e3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clamav@sha256:e0425f759dc31d4abba325dfd4ce979e80577cd0570697c9a6cd321140eba946
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clamav@sha256:560f067bdc34d477edfbb2e3985de4704cf3801c7af59603d1f6be9c80995882
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clamav@sha256:3886aade6066e2db9e89b323dbded93bf698189b7d5decf45f51d75ffa8276bd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clamav@sha256:ea8b21ab88e20196df0dd3ae787a037bf132553900af0618dc211aa902416ad4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clamav@sha256:5612ed30ad306658b14f09837f8d14d6d3eb405f68e1b8c2bd67e3b662b6be5c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clamav@sha256:cbc8965a56cddd14defbee7c6f3648f0cf76fee78d57d8a68658463b5ac5a38d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clamav@sha256:86c8ca9e589007f2f521ba92c4f020108f0e9f726e059f6c1a708ab5476e5676
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clamav@sha256:c6b25b743273e461706ab04f9334636fff46d5328044d1f8dbef15e52153084c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clamav@sha256:23006f330a28f557a2a1c563282fadae6dc1a80a5e4efcfc0bbe8badbe193993
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clamav@sha256:808b3dd546dfbbd96d079bfc1d1c2a1e331af2da417693c04edcd75679607c55