dhi.io/trivy-operator
0-debian-fips-dev, 0-debian13-fips-dev, 0-fips-dev, 0.31-debian-fips-dev, 0.31-debian13-fips-dev, 0.31-fips-dev, 0.31.1-debian-fips-dev, 0.31.1-debian13-fips-dev, 0.31.1-fips-dev
sha256:ffb5824a6d869c2d8327d04b9f0ed6c9aeb5728d25b82bef26f0e173e9c18c67
Manifest digest:sha256:ffcc3aac9708de76af6730b590470aae8101ad2987a18afb4f89f576e28e1e9c
Size
101.71 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/trivy-operator:0-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/trivy-operator:0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/trivy-operator@sha256:c30396ab8af5f34c0490a54ac17e9a98a6c1427eb6a1c09f08f6550e5451d291 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/trivy-operator@sha256:e529a0729efe8f1ae96ef01d7ec208a87d0365f24a29c6ae17eba6ecf922d687 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/trivy-operator@sha256:5b5e8b1c5a1728b9d9c679ca1367ea80f612423667acfe64272ef8f3308e1492 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/trivy-operator@sha256:2c9ec2c8907623c65e7c78f83a206d9d00e647fc5605f2a4f6980aa74e366970 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/trivy-operator@sha256:5d024c55dbd4aba11424d26ddc2950e88b27f416ec1b619ca85a8947088d0685 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/trivy-operator@sha256:7370f1b461db75b0f468d90b60f48f34b6867fe9c8a9324cf371526abf8a750b |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/trivy-operator@sha256:907202302c80b8906087564accc8512fce1b01230b7311a4c92814535ee88fe7 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/trivy-operator@sha256:fdc7e8e86f9ca0f3dd896859a402e04b2c4c11f502d97c6bdc55a0ec46345c33 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/trivy-operator@sha256:c679c3fcb0636e0c8c2968d73ef2f1725af342f3a92f1a3a3b6ebbf6719f13c3 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/trivy-operator@sha256:a8534d51a3bf22ebe597b77a8f00d7bf0010b9d612d8eadceb1225264c8d8e61 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/trivy-operator@sha256:84a6c630024ba099ee5a76f9fe2e0d1a9c85609e2594018de25b706df2533047 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/trivy-operator@sha256:13e33e0b4396bc55ef7bc444944e8ca3964dca76afdeaca2ae4373c7398c5ff8 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/trivy-operator@sha256:52203051b13edff7dfae35e0d94640766a53cfef6cf23767570b4e034aeb5170 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/trivy-operator@sha256:c916e861531f45d95d2e79ccf464cd823fe7b44b601b7ff01377905f8c10d712 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/trivy-operator@sha256:6d08e3368ff8c48d86874c1b0bed878d206dae836475135e5968e61170b565c4 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/trivy-operator@sha256:cdbb18daff8000c0adbd2df1dd575f99d26d8b0070c9b868d70858e75f67ab34 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/trivy-operator@sha256:0123ab2105eb0a3ab1b0582959a4d2f356c301a6f3df7a8f73bcfe4488564959 |