Sign inSign up
Trivy Operator

dhi.io/trivy-operator

Trivy Operator 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips-dev, 0-debian13-fips-dev, 0-fips-dev, 0.31-debian-fips-dev, 0.31-debian13-fips-dev, 0.31-fips-dev, 0.31.1-debian-fips-dev, 0.31.1-debian13-fips-dev, 0.31.1-fips-dev

Index digest:

sha256:52e05585489e1df31ab43aace3bed833a93a9dfc12c10085a075c7e69e5a8603

Manifest digest:

sha256:a533f87ba896ea9fbc630436c097902a1a99d1752fc81be06aae5690edc997a4

Size

101.71 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
2
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trivy-operator:0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trivy-operator:0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trivy-operator@sha256:dd9286b095320c9c3e3722d6076728ffe6f6e7862f3ce4cc0a6b6ed830b91cf2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trivy-operator@sha256:cfa33e1285fe6bad320069d983528a6d9e47289788fd92f060f3555e545a6d46
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/trivy-operator@sha256:d33c617e725e556f1718280dc260f381a0de652db81f4b22e533bcfa45efaabb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trivy-operator@sha256:03426106d1929bec4baf1d7b9b0b6681c1abd43a6bec4a5429f7e1946f89b49b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/trivy-operator@sha256:bc3b5394f9c1ab662aeb0da1a857f71f18719ade23f2fea0c00a702cdcb45497
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trivy-operator@sha256:e0629c45a8f73e8740c92266142ecf1ea6cdc9f4d50aa7790bd4600647bec10b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trivy-operator@sha256:47c9ba38f4030442211c45b506b7e070a71937c7129fa217c4aebb4520a09212
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trivy-operator@sha256:67e6d43bdbe9a1bcd05b7d683cae8818c3085a116605f427ba8c104f83a80e29
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trivy-operator@sha256:506fff2b837d0bdeb55194585ae8ed64c64c42e0a1a5b25a9167e9e71a932cd8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trivy-operator@sha256:6894bfb7726b2200cf9d3ae96525948cea5263f1d297cfa42fe01af4d4de076b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trivy-operator@sha256:bb890393056d3e2b12557e15179704dd677bba2da22f4340f1210ce0cdaad19a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trivy-operator@sha256:d17fd0cac34d3188df20f6fc263b563533a9d8296be419e2eb1e6662eff00c8d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trivy-operator@sha256:9d14388bf46c60b1de34c015ad4fb5651e39507b672814e4fcfa8bcba6de08c7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trivy-operator@sha256:56777a27e90d7043a67c54e7eaa9b7ddacba4f6fd31d6c7f66cde9eace120624
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trivy-operator@sha256:628600b81a3c86c2e963dc1dcc132bbacb4f5f1d88d5bac05f5c0c360db35798
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trivy-operator@sha256:1a7bcdcfbf55f50bce20985608ae8a26b70368b7706f677c780f3b5f47ba8fe6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trivy-operator@sha256:8eae2760b70e1c493ffc4cf8d1638db1bcafb6c4eca5822b999f362c7e8ac62d