Sign inSign up
Trivy

dhi.io/trivy

Trivy 0.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

0-alpine-dev, 0-alpine3.24-dev, 0.74-alpine-dev, 0.74-alpine3.24-dev, 0.74.0-alpine-dev, 0.74.0-alpine3.24-dev

Index digest:

sha256:890959097c42f46293fba3164233c2c75a5f0c2f0ea8dc75da0fb949c3676773

Manifest digest:

sha256:2d9bc7cd9a545664028f04c04d73703cd22b608f7df25a11db2cc56d5b9cd9fc

Size

86.70 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trivy:0-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trivy:0-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trivy@sha256:b201a03eb252cc4dce45aed226298deadfd261fb16d62ea2879fd0abbcc15561
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trivy@sha256:2d47248ba039c95a6177b17f135c0f6a6a3b1db5fb497be722b5f95606a675e5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trivy@sha256:e5845642e902cea1e8ac67f3c6a91e346218e4a14b2e1349612402a6e6ba781f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trivy@sha256:e1a64d0504ea32f041287da244695bea81923d4418e55425e5bdb44eed27755d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trivy@sha256:07d1329a76f1338c4c4317416f7ce80e087150af5032c88d19456ce808e229f5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trivy@sha256:ac16882df283c700425659ef0aaff00a4fdc1934fc1476f8c3f47e473185ade0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trivy@sha256:22bcb3176c8b4db5b9a06c413f75c4e39e263a025159a7a92a7249dcd5b737aa
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trivy@sha256:477c46f7668fd8b92e5ed9fe0c0271fbcc6812cf38efd1933fc552710451c5bc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trivy@sha256:6b37c1c3c7ae359fc97ade3f0fe5cd9010018fd06ad50e603eb30eb13035942d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trivy@sha256:718ed8c9297d291955bde1b9d7b0d85991966efb1b6ce065889765d803366293
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trivy@sha256:d67d4e58def8e4a349997464df5695e25794320ac888c1f7658909361b2ceea7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trivy@sha256:3f118df99ffc44dc7190c990285bd3b66fe9be285f20e14448a23472243a1c2e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trivy@sha256:054e39099afb72c3e1529ef226b8c4c679c5b96df26cf1f3981f10f22b8a8275
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trivy@sha256:1d87b542eb079bd2346001650f3ca70bff7dd90f2295b5593b00e2ae52a99a65
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trivy@sha256:b508b08d8849a234aa336f4a5ca45a4ff46f83e09a0703ab78e02df85c68fbdd