dhi.io/trivy-operator
0-debian-fips-dev, 0-debian13-fips-dev, 0-fips-dev, 0.31-debian-fips-dev, 0.31-debian13-fips-dev, 0.31-fips-dev, 0.31.1-debian-fips-dev, 0.31.1-debian13-fips-dev, 0.31.1-fips-dev
sha256:72d55125861e8d4e74766e4a2d8b194b43b03e0fcc942f29b3527dfc1ddc0231
Manifest digest:sha256:ac03f8760f3cee0b01112ee94b356ef5a192d174e519ad993b9011cb5efb7a0e
Size
101.75 MB
Last pushed
4 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/trivy-operator:0-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/trivy-operator:0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/trivy-operator@sha256:b6c3592f696b636c64e3c0efe050df43acd8d979305a61fb393f573cf15bf422 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/trivy-operator@sha256:635f3a55bb73c8ecc065ec77d66c99e2febd7d8f263634bdd4b644d74c4b14c9 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/trivy-operator@sha256:56bae23e3d38a285b21932301176f67e2f2b09b0cd3ae9b7460c51d77359cd57 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/trivy-operator@sha256:27502e741f9691b16e29b3e95616a3446ad7bbbdad1c29ff70f8eed75f46d0b6 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/trivy-operator@sha256:f4d9a00562b38a4897212254273c70d89286b6b9ada32f36162f5b91155f8392 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/trivy-operator@sha256:3e6cb26c231975f978a827ca73147de3e047f6226b5fa21f2b045e5a502093f2 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/trivy-operator@sha256:8a25e1d0f73d808689821026432adf55e235551208ab613f7f8e4cd09cf6e68c |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/trivy-operator@sha256:e01367952bfc08529763e5e87fb169d5ef766be8dfe02f86205be01b271047e2 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/trivy-operator@sha256:e2e6878af9a1285c15935b78dd948910fd615f21dd26301f4d3488d7e61a762d |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/trivy-operator@sha256:73463453891a3cdc3f102f774c8464c26afeceb01aec1503ba6754759fc5a609 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/trivy-operator@sha256:0f6a0aa3842954a792d8ab945cf3ee64633ba94b58a5583a0d68f4f905189e82 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/trivy-operator@sha256:e3b71d94d4a307db50544d4dd59636791a3ce2a7d8794b0bed29d9be0d321a75 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/trivy-operator@sha256:5c385574a36e254852b44473583f0ff3e25cbc09c5b15dffeb0340c1fd120d83 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/trivy-operator@sha256:7d0c2dd41a8aef5586f5ece822913ec05059902cad189e8c9037d8fc9baa5a5e |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/trivy-operator@sha256:afa173f931344fdc984a6f76b6674ef550da2866b4d2c154f0f5049d6f62ec97 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/trivy-operator@sha256:ef005c3a979133e4dbf29559a7df1a3083ab9b64a751c36ba18c96a9548b0fe6 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/trivy-operator@sha256:055a165f358ee59edd0471c8050acc8326dc6479726f17d21878ba67d73568a6 |