Sign inSign up
Trivy

dhi.io/trivy

Trivy 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

0-alpine-fips-dev, 0-alpine3.24-fips-dev, 0.74-alpine-fips-dev, 0.74-alpine3.24-fips-dev, 0.74.0-alpine-fips-dev, 0.74.0-alpine3.24-fips-dev

Index digest:

sha256:ae56649913ff3eb4fe4ab2e013fe18584f43fe10f809c1381c208b1428c7e34d

Manifest digest:

sha256:329f04dc53fe2593b9103bd9d50db685922554ffa45635ff9f15a32a1e33a655

Size

87.89 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
1
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trivy:0-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trivy:0-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trivy@sha256:cb32833660769a181cece55fe22696713219e0443d7a40c6da35c46fba4c59a4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trivy@sha256:620536d74f7a288407c2bd6936a35ee835c437fa534aaff4ba576624af5522ce
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/trivy@sha256:9a395d5882376d29ebab4776e914a4e1bcea6d3fd8b35c21c413491e389742b5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trivy@sha256:266d89ce29dab5e7f6d179d947c75d700929de614d7c9cf69dc9eeca389a5685
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/trivy@sha256:eace626a53317a358da2415819820e2edc1ace567c51fae804a031bbd6ace40e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trivy@sha256:310a2a6dc5d88d69da1acefcfc07f070da968d5b9a1b7cb33d06c710f184b446
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trivy@sha256:fa2fbc90035c0a67d06565d952df9d2899ebb5535319e5e15ba6024065e0006a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trivy@sha256:8dd8ddf3922d11672f88083c65db11aa177f8966d6987a1f22ac0064c2f72e49
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trivy@sha256:403b72adeb00bcc32ded42787ad1708985763980b494f795b4e58eec757413e9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trivy@sha256:81e0c6316ceff4aca9d6c36c16b09240741fd10766f409e8fd1870454c7d4114
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trivy@sha256:4996b3f09d4496fbfbf75b30d47a9ccf2235206933c6347ecf4570439be537bb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trivy@sha256:e28a1b3c976c570f2931873ede481fe216293ec5674c844b9f56b0b39b528c39
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trivy@sha256:d88831d8d2e57b2f7369a7d18365e36bcc048854cf8ee28188e0547e56221408
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trivy@sha256:7b3c29e0ec9612263848560643b92e1b5832323a4cd4432a17cf0e053b44e479
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trivy@sha256:8a9d98d2a22b837e19de6f1275880602bcd8fa2f0abe0aa41b14aa7a555f3d00
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trivy@sha256:9c2c02e1abdf350423ee51f27dd26998598d34e3f15487abfca76fd3c1598377
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trivy@sha256:08bc9aac8eafba2c45ec45ef598f96cb33fa5c8de1a5ad42e45805d724cb96e7