Sign inSign up
clamav

dhi.io/clamav

ClamAV 1.5.x (base, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-base-fips, 1-debian-base-fips, 1-debian13-base-fips, 1.5-base-fips, 1.5-debian-base-fips, 1.5-debian13-base-fips, 1.5.4-base-fips, 1.5.4-debian-base-fips, 1.5.4-debian13-base-fips

Index digest:

sha256:c311e0f8b08ecddf38350db0116f2e386e3aa113f85d457d56d18fb600eed97f

Manifest digest:

sha256:0eafdf4688ea99bb97416dd15abe4bc8ddf79149f2a974ed6540a2822fcdcb8c

Size

38.57 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clamav:1-base-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clamav:1-base-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clamav@sha256:3c2fc6675a5cad7d5dd827b7273fc97da87399a7cd49d16d238a55ecb07a85a4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clamav@sha256:d7cda3c188af6eae5f3976c5a9f42ad465cd3391a2af4e32b072484bdba7f6f5
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/clamav@sha256:c6b2af17c10538eba8cacf5407d42b8007697c4202b805973519779f655a94b1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clamav@sha256:da983de17ca0515fd0b3cee60ba15a922ed83b9045971eb38f1e333bba0c3864
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/clamav@sha256:b768de5d7192d103110904a6175e64253550cc90111ce43c3c231d2f44c0a486
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clamav@sha256:6d747fe71558c335725e94e58d679de3b82820c395da42494e0f0eb1a7210e0a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clamav@sha256:29869ee95b899c3129eee14195cfaa5ec0e44ee97b6991cddd6fd39042ae3480
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clamav@sha256:308907c4cf025abb3b792dff89239352345dae823c316ffa4a780da02d60d8f3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clamav@sha256:0e7071c680b950417786b7e628ac40fb18202b46468d3db8bdf043cfae99bbe6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clamav@sha256:58dcfb5d57d0dfd6bc7ea9ca3b13319c46259b119fdc5d37a1789874a6ffbd62
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clamav@sha256:77bf74762fdfb76ba75e719eac6f603921310fe1cefc3ce72a4f56796c57fb59
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clamav@sha256:f457534363cba71114f9eed34198df3a4e4647ea6bab99d0d9361defe5aa9fa3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clamav@sha256:40e6032587c8edc39f90326fbaebdbe7a39256ab96937e833d20ca3495d9d51e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clamav@sha256:8d886e6ae2a81c53eba09de0aaaada19b3b3b3ce4c3c678d73c460ed9cb7804f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clamav@sha256:ba1a9dbbf93cfc9385c66a73836915f928dadff6d611d352193e2a37b51f180e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clamav@sha256:af0f6d84bab1202a8ffe527ea79fe27d3fb3306caf245da0154d92916985dafa
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clamav@sha256:4c75584f9552b2ff1337dc291106a21b3139df6344d6ad6494b265f47c5edb49