dhi.io/trivy-operator
0-debian-fips-dev, 0-debian13-fips-dev, 0-fips-dev, 0.31-debian-fips-dev, 0.31-debian13-fips-dev, 0.31-fips-dev, 0.31.1-debian-fips-dev, 0.31.1-debian13-fips-dev, 0.31.1-fips-dev
sha256:03bc38077cd4c006504f8bc99ba1afb9943cdd1c75e7d6ee6b2cd5dea11f3771
Manifest digest:sha256:78535f759f4e42663d760c34e76bebc2b2ac6d3c01a0bd482de8bdea755710fd
Size
101.71 MB
Last pushed
5 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/trivy-operator:0-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/trivy-operator:0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/trivy-operator@sha256:ec45907ed0179568542e7ba6c658249da0f7e492e9c291c7ac6f048b8e85bbe7 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/trivy-operator@sha256:a94b8dae58f4579e0209d3d819f7e6fcc09f0ac7a4602853d989eab08774723d |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/trivy-operator@sha256:7ea1a5d1beb9fc3ceacdf2f53378ae7c110afd00edf853cec69a9fd8a95b7723 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/trivy-operator@sha256:c679a5061d82e5e4c46f5b584f7c627398d4df387ade2864e7a1a676994cb615 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/trivy-operator@sha256:aff1cbf7757c903fc07a80a24bd6993da9724cf44db1772b1f49bce42e621537 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/trivy-operator@sha256:6ea905034232b36c0da5519bea7778a43aa3e243d60246fa32c92508e2ee2f03 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/trivy-operator@sha256:a7347aee5434bd2f47fe81997a9d29ed7b350f793f875ef40b9f52beb1c609f1 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/trivy-operator@sha256:d62ab3942830df94e4cf686df98ccc5e6a829e3efbcbe4cda14057442b790cb9 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/trivy-operator@sha256:12d35f2396b6e12910a3905e74e1ee4c83708548f3c80134a96c4ed348e96166 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/trivy-operator@sha256:fe7037ff44826ab1dbae34ad28828094147ea584b7e2025986a2100907c9c692 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/trivy-operator@sha256:098052fceb1d9e68baae902b71aaaace4d04a37e2c739d421fcfaef464e1899f |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/trivy-operator@sha256:73e6007eb4c59a9d439c4d121479b3af978ae1d26726a6d80c04552002f45d1e |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/trivy-operator@sha256:63ac23f3b50364ed0bfdff95f643714ff6dc69aecdfe304c75701b5785d75e9a |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/trivy-operator@sha256:6b8124e872d58049d2847400675bfef06e15152f29ff8ca81a7da8aa2178938e |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/trivy-operator@sha256:5cf59a9e8e3d0420b5e2ad471e29244ff0744f5a0e3ff3a2797abaa5fed2ed88 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/trivy-operator@sha256:809759e77d521d6a971cc8a9d324eaa97821c83b54f03714fb90e469f832b144 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/trivy-operator@sha256:315c481fa758e7bc49a04410483522576e0c5f14b03c8b469554f8f8489d8671 |