Sign inSign up
clamav

dhi.io/clamav

ClamAV 1.5.x (base)

CIS
linux/amd64
debian 13
Tags:

1.5-base, 1.5-debian-base, 1.5-debian13-base, 1.5.4-base, 1.5.4-debian-base, 1.5.4-debian13-base

Index digest:

sha256:bce7782256c381eb2c487749877194556efec40b7ac4ef686255896c67faec68

Manifest digest:

sha256:5dd2f6da14514d443e11f7f5187a966716ae917a0ccea73c0a40b98809a0261b

Size

37.83 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clamav:1.5-base

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clamav:1.5-base --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clamav@sha256:b7088a7d4883aa0a0780d2cc16abd845b9d5aca341881849b2bddf009bee2f69
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clamav@sha256:1965c58cab293710d0f0eef5084af9bc6dda7bf7a5248a68791d8250e9e08893
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clamav@sha256:3bc2852683da17ccf3c4644fcdbae5f4feeb2404909fde4f3dbaed8b501fa68e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clamav@sha256:77d5a244f589bbdca444534af0b60a278ead0a3bcf98997d5c058ea6cbf85e09
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clamav@sha256:bd2222a4e10246ffa68aad25fe2fd497f39cdf66ef76b759700fe6c2bc2021f1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clamav@sha256:e374f54084c177b5fc32bf39ca9b1d9f2f73e526ce4b928b749b7ebc01607fb0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clamav@sha256:c8d0e0c7bee5f260c08744f7f266f58d13eba93a5f488f8f0b6383cd450b1539
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clamav@sha256:0ea5abc459aacd70dee4e6d028379cb9b3bcdb24dc227abd73ac9ba71333fa39
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clamav@sha256:e138b8b59d430ef47027e04d0a829adc5398d71171208b7fb2d6980b3bff37d9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clamav@sha256:1693397977ad7a5cbfb5b0895fc61364e06fae22e2e90e36d7cbbee85776eb3b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clamav@sha256:d980ba6dc0c219f1f103df9eb820b7299a3d1506a51b0c4855d81768e9a619ac
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clamav@sha256:c06775c4611684d4af531beb78ce13e718fe8cd6c17a9aa7539d3f21c1f47826
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clamav@sha256:b5a5c65bda99754a844aeaeec462094185514ec8a6d062c9c6c6d78fac38ffc5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clamav@sha256:9c6b85b8cad93f41d5eccd9d7bd35d89cec7e781689fcd01f301629ca31a9f71
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clamav@sha256:b2286f595aa66eaf31a5ef3b4c3fe7c35c332750b3e4370be0b90367a47c0eb5