Sign inSign up
clamav

dhi.io/clamav

ClamAV 1.4.x (base)

CIS
linux/amd64
debian 13
Tags:

1.4-base, 1.4-debian-base, 1.4-debian13-base, 1.4.6-base, 1.4.6-debian-base, 1.4.6-debian13-base

Index digest:

sha256:de63c7c97defea04cfdba5f7252a47ca0381bca52e66804ce404098af37f4533

Manifest digest:

sha256:5c7932e68dff2c846342973ae047bec425b064737ab9f98df35caa2fa2eba6af

Size

36.06 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Aug 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clamav:1.4-base

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clamav:1.4-base --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clamav@sha256:b5c4d9e88287da1d0f1c818cba680bcd3c5da1893e727385a48b8b5cecd42301
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clamav@sha256:c3b05f92cb045dc1553951335eceffb1e2b92cac323652a6c3019224bab9fb21
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clamav@sha256:2e4578d758f0f093f79abeb0ea6ebd6f11009b6b6b566e09266457ceeb03d172
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clamav@sha256:2474f6a79ddbdd36d05988ee635b6c4b56d9f856c899455afae7fc94365cb904
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clamav@sha256:4a1bf2b7bc1cd7f3f2ca75d37557cb5618792cd4c7cc3b63678505e0615099c3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clamav@sha256:ce5abe46c37dd61adc0a85fab0d2eb760d19489d6bf57f833f1ed1a8b3cf8521
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clamav@sha256:26ecfb66fdb791b9fd9d291fba95a6964ca4d92deae11ea227ac932f07dc1dc2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clamav@sha256:31f4b83d8df06bac60bf05f09f6add506cbef3e6ec3cf9e6233aa5374409a2b0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clamav@sha256:7cde56099bfee7320dd895e7aae8774adaa8c6c1f26cfc7ca52be6e00e4765e4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clamav@sha256:1adf25cc16c248e98149ff37b1f38f3a7655e0581e648b4125c42deb87af7aca
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clamav@sha256:054971462b1a0c47e7439f61b896d13ca5f59718782525e1543bd11f5fece87c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clamav@sha256:62e0e7370a900b190656a1b417bb14f337b20ecd8e9e11e1d154b191af8daf2a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clamav@sha256:cde79b51af3d3a392dc1a943c722a9ed6a084ce9cf2a78f4b8bea02d3a34e9fc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clamav@sha256:052a02126abb35518492d6f89f9358f2098933b5f372df6ef381056d9951cff0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clamav@sha256:dd7b69864b254e6e1d434658512408748631285d63b11bdd555b7a36f1ada720