Sign inSign up
Trivy

dhi.io/trivy

Trivy 0.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

0-alpine3.23-dev, 0.74-alpine3.23-dev, 0.74.0-alpine3.23-dev

Index digest:

sha256:65a4902aef15b37fced285ab09cc6efd490cb634a2ec7321f1b8c5e7ef0919a0

Manifest digest:

sha256:0db991656f412553dd951b99679e8eeb74eac30d2d60d2102874c76ca53a9ef7

Size

87.02 MB

Last pushed

1 day ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trivy:0-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trivy:0-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trivy@sha256:3a5deb08d4776272fc2cf321e6d5dafb42877575f2af54dea528cc1e03086e33
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trivy@sha256:1e22d45dbbe40b7bc69baa7dc419ff1b94e52888244a74407a190d8e7b80ddc4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trivy@sha256:17a0c06d7415a97529eaada5ee9ee4951e3bdaf17ae6af368dfdf771089abfcf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trivy@sha256:7161dc2f366c4915c8954e617be8ece6fc9ba500f0a6996512ef046bf4be4d93
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trivy@sha256:78e5e7dafca85cb466888e49edb8f96bce2b4f23fd42156f41649194abf1abe3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trivy@sha256:80b2e9cd9e01733b42547136dc1aabb8d79eece9703af033686a8940d173d058
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trivy@sha256:9a1ef5d3969f5be9e173cff34b28e7649cd8e4a1e3a96ebf99880bf92c8ad4a0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trivy@sha256:8550723187a9dc3427a2c6b93f3beb1cb065b7e5c7d7354425320a93a1f34f55
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trivy@sha256:b1300f995e4e1595ca2089b79f54afe054cf68c51fb823e6830d35d107b620b4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trivy@sha256:a11e6a959a579c1c6cff788ec3144061ea0500b341aaced505437030a702af51
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trivy@sha256:5d9e86487b5edd855a643233bd64a644c077bc9f1feffb8130eac7cbebf7a60d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trivy@sha256:cf66d481c49cca5485dfe1386390183237f1f08b0fa300f567fe1dbd71268670
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trivy@sha256:d36cfab9742ddab9cd90dcd92473f36a105d6d49db93f75fc1fe2e4839bb985f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trivy@sha256:408de636072f5df9929344c33e928a6f07e05d324cceb93ee865f670a8c4f8d7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trivy@sha256:e2b29e2e9e3f3fdd1c7caf0bfed7ddccb87ac16b335d9720a32a41c1c224236c