Sign inSign up
clamav

dhi.io/clamav

ClamAV 1.4.x

CIS
linux/amd64
debian 13
Tags:

1.4, 1.4-debian, 1.4-debian13, 1.4.6, 1.4.6-debian, 1.4.6-debian13

Index digest:

sha256:66eec50db5cc01be81260eaf767c862b06fb3bb69e4552b22dec69850b01a67d

Manifest digest:

sha256:d9a18f901b9d0c02db5657b797a413b25604d82614672801a42f382130663fb1

Size

143.61 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Aug 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clamav:1.4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clamav:1.4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clamav@sha256:6a4bd330356ebf49b08ad40994509561153d09ac46a2a517ffd708a015dacc5a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clamav@sha256:6b5ca00f34b721935fa631e523f6cd0727b9196369e3187ce0f8b96eb1356fca
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clamav@sha256:a5f5c21a0c5901d0406ff46a825ae59987d8d4450b4a3d2e1f3d23585a0bfa8b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clamav@sha256:86bfc8c8aab56948993ad8ff5017483fb5830f19fffadd79a941fc53aee08c7c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clamav@sha256:f714281a5e1fb5e8b367aa427f78493b7bf461f6b5379186c72a7d79b29dd84c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clamav@sha256:993dc4b308d13dc041d8c811579d165c96e0e301df6cec40ab5208cbee13021d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clamav@sha256:9913239becb46c43e40967fbae0816a1510e46464a2236e8cc2ed9fed6cca436
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clamav@sha256:a49dd22cef45d5d57306789774a7112e1d4980ecfddd4ea374fd4c4639466bc3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clamav@sha256:1c0911ba3e2d4ed220949f76500147e4a44766adfd0674d17430dc7fc24bda0d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clamav@sha256:ab82424aaf02e94f9fe324b1a5e76b6fd3b61ab9252e8bfcf62adb92ccb919fc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clamav@sha256:ebca9c7f711219a14db53dbcdaa01db9a7ac9242f4fa7aa56ffe8f924c22910e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clamav@sha256:2a95d28c3e80fe96f720a8e2dcdc0367a09f1d39c6389026cd82654fe976a2f8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clamav@sha256:1c1c576b1471f00c456a86693bc6cbb107f52f5b1da4b4226d4c4d0e213881ae
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clamav@sha256:153d2f97c60ebfe2d49efe9ae2d2bc04422e68ba2068fe24905d63386f3c71eb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clamav@sha256:c4b7df54be799dd5b6d891f9cfece1fb086f75906d060d7cc28c21e81dcb3146