dhi.io/trivy
0-debian-fips, 0-debian13-fips, 0-fips, 0.74-debian-fips, 0.74-debian13-fips, 0.74-fips, 0.74.0-debian-fips, 0.74.0-debian13-fips, 0.74.0-fips
sha256:1146acaee9c888a806d8a16c594162e9e1ec74a9f825e7fcf4f32ce337e8ea72
Manifest digest:sha256:0ed6f25dd3ce46bc1461bb6f8f9bfcf24f87f2620a105a7a2ee16759dc7b9546
Size
51.48 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/trivy:0-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/trivy:0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/trivy@sha256:876c8b8346dced98ac486ce6c2a53b602e4ea46f1a2c3461145a309bb4cf1478 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/trivy@sha256:77c06305d24da4e640caee6c227582f6ee3fe3edb277d901b29d69dfd1386243 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/trivy@sha256:079c6caa09f1a78947f74d739b6a9ee6e48e80d5cd092cc0b598fb10fb00f536 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/trivy@sha256:09e36020468cacc23110aae2817d5c5de544ed805e5e2c2aa16d9a709271947b |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/trivy@sha256:07be68314d05b31bd8045786c75e2f4a0a2faefa949b60e09a3f0983abe1ac85 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/trivy@sha256:de7035633cbe38308978d03480576f2aa25324699d9251429ff7cad46f5f45d8 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/trivy@sha256:73dae8c178f6713d27bf7de22cc126899f6b5873f5b36e4cbae0fac53ac8ab3d |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/trivy@sha256:d87953fc1b98f525a235bc998b9906a7de38b3f9224f5ab9de37ecfb219d600a |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/trivy@sha256:761712025e694777bfd78f6f3ed20b309a969069d113cc5ce4f07dbdd153f6c3 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/trivy@sha256:23263395f7ca4e2884cf6729d4ebe9632c6cd8e74d02e3b19248cadaed22c4f8 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/trivy@sha256:e5b219894b93b2eba81e7c6cb9dbd11d57871eabf8830705e872401fc728a44a |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/trivy@sha256:2e217c5f0958baa48b9025e4837ae1d25930baa1683947e8857bf83810826a33 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/trivy@sha256:0e5a2aed476139fddb65b89cd6c2a15d4b56f3bb6a7439fc7e4532bb1307423d |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/trivy@sha256:1b4fbdf22e4e367c70fe2fabc71385dc61a2666a35dfa36eba5f2efbc59c453e |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/trivy@sha256:b98c4c0ea70c7d05a8b3f8d0329ac8b5bb33175c2febf13edd5737201d622b8d |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/trivy@sha256:e0e52d13edcecb1e8a76c3d423b34804c5c920d0fc56ecd96d43c27d8191b9fb |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/trivy@sha256:947afff302496b0f43e41ab1ef58efcb19e39f96a708a6cdc07b43194852d13b |