Sign inSign up
Trivy Operator

dhi.io/trivy-operator

Trivy Operator 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips-dev, 0-debian13-fips-dev, 0-fips-dev, 0.31-debian-fips-dev, 0.31-debian13-fips-dev, 0.31-fips-dev, 0.31.1-debian-fips-dev, 0.31.1-debian13-fips-dev, 0.31.1-fips-dev

Index digest:

sha256:1547ad612ca9223ff4e825de80fc55931ca9243ccf9fcfe58c48148e76d779fd

Manifest digest:

sha256:973eb423714084efbdc43b0d79c43d3452222a69748a4e4851d122453e6a5aba

Size

101.71 MB

Last pushed

4 hours ago

Vulnerabilities

0
1
2
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trivy-operator:0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trivy-operator:0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trivy-operator@sha256:cb7fabe166046e65ddd8fd10e968918fbe5dc79cc0e494b8f7e522aa8a64e6ec
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trivy-operator@sha256:005e88343779d485d9cc474b905f70f50fb5e107b7c0f764056c3faa193421f3
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/trivy-operator@sha256:6b461291afd46d7391e9e9d10acbca17c5680ce904aafa6f575449bb8f646a51
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trivy-operator@sha256:b1f905a0b51744073725b144a7f227612a21156bcd37853d9efa528608e091d8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/trivy-operator@sha256:ee06a897064bfef0fa5f5c33cc9b65ae71294603e6068831ce80987da1d8a5c2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trivy-operator@sha256:4775c65b527b9903d86b096a66408850ba7eef71401aef74ca3eed61f3484d0d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trivy-operator@sha256:aebd3591d1ae35b190343607263b94292d91c535f844a0c481cd53aecf618d19
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trivy-operator@sha256:cc11918500691f10b32c72569b2f86974f0c3acebbd90a29557af17660f52d2e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trivy-operator@sha256:9f4c2849563c0376388923e36713e32affb7d746994c491a55ec6e30b6f5fdb0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trivy-operator@sha256:c05e281e2038596ebf760acd68f55469629e99dc1f2fb0b7de3ead921cd14bd6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trivy-operator@sha256:e6a52d53d0bd4a0c1ef40af9d13ab5b82f1756511032c88fa4fd5400e58f5ef0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trivy-operator@sha256:cc1ba29dce572c15346f84fb9f9d3398c9c4f0f7870e6b5d54ceda6445361f2c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trivy-operator@sha256:806f2dea50afc0864bf03c37fd9c3adbc11e8311da258f73f526b41991190a5f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trivy-operator@sha256:d2685f8921aa9501f4a85d20996fe0a040cb9d344b82207ccc871abecb0bd8ba
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trivy-operator@sha256:a27dd178110282825b4791c4a089372d4f381e4d9e89f2e3ecdef2096bcdbf63
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trivy-operator@sha256:800418c9bbf876bad677509cfae91165cfacc76afa90cea46356fe62e9ffe4b0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trivy-operator@sha256:3354e3846d9ad49ee22b64b0320d63a9fe8ce49d447fcb5650476e5ca79a6ccc