dhi.io/trivy-operator
0-debian-fips, 0-debian13-fips, 0-fips, 0.31-debian-fips, 0.31-debian13-fips, 0.31-fips, 0.31.1-debian-fips, 0.31.1-debian13-fips, 0.31.1-fips
sha256:7f0552188d54a7d489b1fecb55908d2eb1efe7805cf71736fb0fe2ba59b91aba
Manifest digest:sha256:6fdba3fc00a8ba791d23167afc4aba6a77e1d29f00bf6b268bf3ef9b4c745e8f
Size
49.06 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/trivy-operator:0-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/trivy-operator:0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/trivy-operator@sha256:50b756681c59b6b61022df6912fb35cbb0d72cf97d1516988bdae49c34f546c5 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/trivy-operator@sha256:5375829d158f5aeae6dd926802f7825a44cb210f5f17efc6392ed0dd7b245489 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/trivy-operator@sha256:1c4aa6cf19014fd11e7ebf4c6484e68c5057164ab69164581ac924b40db62005 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/trivy-operator@sha256:6b10bd22c8c67f16f30606b4e8203ae682bff286404a587f796f188b53ef7c16 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/trivy-operator@sha256:cb7bc080acd2e591a1c1511979ba7e8bd692a496eb2e4664ac86af564b7685d2 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/trivy-operator@sha256:f0214bc3b62256ebf5a05617ccc0ec7ee2e89f7b2a57fb862b25eee4b8d30b8e |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/trivy-operator@sha256:732b4283f3a55611631178d20db5c13153aff53f65abcfbbfbd75aa58f88c302 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/trivy-operator@sha256:7f82e1e638c67a568b15b517e3098f3bf5adfd9d0224cf6e92805bd03b67727c |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/trivy-operator@sha256:c2180705c7ef9a0cf66b1a332caddf8ec04c75af971dafb81dd8b8cbc7d86a79 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/trivy-operator@sha256:fa3097142fd6f7cf73a1c2077039baf73bd5a5fcb00ec9d9ef7a3762cbdd0989 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/trivy-operator@sha256:fb63ce2b215703a52ea37fc4c25d9c9a5ca4cc8737b2b7707f65d6b7b34f6e6d |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/trivy-operator@sha256:ae97edacf841510babf210044e4062025d61e1212c0dd41f76e938772c4bd304 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/trivy-operator@sha256:69844f4bff6703867fa05d41727224a0193be4d5889eeb942afea1af9781e4c0 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/trivy-operator@sha256:2e893751e50edcf41618ddb02a3924ba284600ed9c939c0a572aa923c0f890c8 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/trivy-operator@sha256:35dcc61c960c90a5c98e8134e17c954e594b69312fd8f9d30e6b79056cd2d6b6 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/trivy-operator@sha256:54f0077be45f47f053c81542d52c42fd45089ca02e95a2a2bf2cd1e5d96176c9 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/trivy-operator@sha256:cbebcac2937a81bd84b3db597d11e095287f9c7bc9eae936cff465cbce1ac624 |