Sign inSign up
Harbor Trivy Adapter

dhi.io/harbor-trivy-adapter

Harbor Trivy Adapter 2.12.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.12-debian-dev, 2.12-debian13-dev, 2.12-dev, 2.12.4-debian-dev, 2.12.4-debian13-dev, 2.12.4-dev

Index digest:

sha256:4e9ad2ebb61a6f30a23c3fa7dfcf2356af3feb0bb33680a4ed041f1cacb262bd

Manifest digest:

sha256:79fb1cb691fc53e1ea69db5f7727d8ec0382ddb4c5840c4f2cd336889c66e027

Size

74.24 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
1
2
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-trivy-adapter:2.12-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-trivy-adapter:2.12-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-trivy-adapter@sha256:2530facd6670d2dfa282ec6ae2f3fff7dc56b7799286031a0708b8af9ce6bf82
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-trivy-adapter@sha256:e1578f94975cb71b091301a19d7cb4b9463827783bb9636a0d94918ff9ec849c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-trivy-adapter@sha256:77c076ca217e6262dc470eaaf575b141712f86dddfe51a6e0057fc5414362df5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-trivy-adapter@sha256:c994985ba69747f48ce301feb04328ad60aa7f80d8aced557a30fe6cee0edbd1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-trivy-adapter@sha256:44be276e17bca910005123ed260496ff570c34d7c5145608a3d0a38fa98a41e6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-trivy-adapter@sha256:c55992f63c25dd45c6fdc372281d7c99657245da58a7867d416f3c77d977f3bf
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-trivy-adapter@sha256:e1e3dbdbd9f88aa6ad8fd62a1283f9af7008d2ea6ed4456687aca536e8db2442
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-trivy-adapter@sha256:e7caef89fe06c7e1b8a8cf25b18664460e42b4c6ef000e9eb82aa55085a17da3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-trivy-adapter@sha256:987dd839d65a5a76862af8d2ddd8326739a883e2f9d428a3d5b6c1a9914633ff
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-trivy-adapter@sha256:6670d9c6e0f489f273d86c4c7214c6b4b8d01d6ceb5212afaa0640c3a99c197d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-trivy-adapter@sha256:33345cd581e37d1527cbe03f49486d366f8f734f4389155d35e1fb406af584ad
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-trivy-adapter@sha256:96b929387ddce281e98124518922cbf6bbd61e3b5348d425104eed3be4ffe0dc
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-trivy-adapter@sha256:eebd722406dcf1dade47228f8e353582ecce308d5d5491bb90a397c798773d1d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-trivy-adapter@sha256:d6e17bcd28f105c424330e00cfd58b254148f6783897c97a5ee6c6b375d97163
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-trivy-adapter@sha256:ada4ac35aa067f57ad526d2407abab3900828f97e9ea7d47b87e8db415af14a0