Sign inSign up
clamav

dhi.io/clamav

ClamAV 1.4.x

CIS
linux/amd64
debian 13
Tags:

1.4, 1.4-debian, 1.4-debian13, 1.4.6, 1.4.6-debian, 1.4.6-debian13

Index digest:

sha256:b570cd1be9b78040e83b1d515a31b99e754cc650ada11dad064c145a7a2e9509

Manifest digest:

sha256:13fc80dcf31ea48b547d4f8c5ec74aabcbc4e46ca03e92781e4da628df543972

Size

143.62 MB

Last pushed

3 hours ago

Vulnerabilities

0
1
0
0
0

Support

Active until Aug 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clamav:1.4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clamav:1.4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clamav@sha256:fd46da0ceb3425f7238d561c9eb47939e92ace780856c573d64aeab4f67a5068
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clamav@sha256:f25d24cfc8d73851e1d7428d2eecf30a914fecbe4471bbc2b02d73b282e8ed72
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clamav@sha256:f879dd10ae524acd96d510502c2ec9214d28c20091304566efaa1dca851691b4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clamav@sha256:574584345b1d15c1c61c3bfcbe462f132863eeea5e6a85244188df181b53ae0a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clamav@sha256:c33901043f65f49b492be986b501432e06bebf274549a9493b30cc748cffc017
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clamav@sha256:ac900476326b1009c22f9c3a0f4cac2c6d61e6421e036b26f6ec0f4ea58529df
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clamav@sha256:29ea26b3e7c7873195fc9028401e7e9a0b763a7dbcdfcfc37ccb5e4f011b2b43
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clamav@sha256:1a0dbc7296ea9d131da96c2a2556aa649cfb992c2992cd4492e8f0b60414a0ae
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clamav@sha256:2f31602eb73db6d70cda30903c7fe7d777e5c6b5cdf2a0bb632cf9e92f4454ef
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clamav@sha256:7f0f2e1084ae5f8920e025202629fea3ff40b52e24d928a703a8534ff55d6392
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clamav@sha256:46a24325f28b783e29b3b1e1e5615e4825810f1e9e5b61daee1d5d9e50266180
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clamav@sha256:bc7a3e1c01cc96c52d0f3f09b7ba3db315a6bdaeb88e89c524061a82edec8617
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clamav@sha256:c51e2f5878b6d634853ce4521d319464309a058b6ee68a1708399585a6c5694b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clamav@sha256:41817163e0015e28adcf88c0743d02fc1fff6e6ec66da6ecef2e2e3292772a6c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clamav@sha256:3504e28582eed2406320c36f28f460ea8020a04f9ea5c456a5bb2601927ef682