Sign inSign up
Trivy

dhi.io/trivy

Trivy 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

0-alpine-fips-dev, 0-alpine3.24-fips-dev, 0.74-alpine-fips-dev, 0.74-alpine3.24-fips-dev, 0.74.0-alpine-fips-dev, 0.74.0-alpine3.24-fips-dev

Index digest:

sha256:1ce0c5d8a102816b789aac06e0fbb1d4f2c34d89f87e4e956e6845ac533c5634

Manifest digest:

sha256:68b35bc15a0369e0e75d5855d3c11f4e7f9a1ceb5f8cd895c2745888aa8f512e

Size

87.57 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trivy:0-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trivy:0-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trivy@sha256:d6ebe56902714c1a93c4321ea9ed48a521734c3572a4f0c875304bb1cd736204
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trivy@sha256:3cda1bf9fdc4f9f31260328bc26e6f43c60274164e44d8572ec63b3db226944c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/trivy@sha256:def985782a61f6fb288a0ac4c53818c36966fd8a4593e310b0c7fc05ca5cc2e3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trivy@sha256:018e25469d4eb70e64f0331fd32447033b974930cb0f76f287cfebd0e44bfa02
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/trivy@sha256:d6d704df6b83e87b6993eec5049190c31fd0545e8e3bbdf93ce32a1b05aae432
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trivy@sha256:1cef6cfd1154ef4a6e4560c0d4a979ef3571eb1f428dd2a12f9c59b95f2d46c5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trivy@sha256:75c7aeeb4f006172f00db2a35f9a37090acc63d7b7b909c7c4fddbba647167bd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trivy@sha256:ef0c41e73b278bd560f72ca68781e9333114eeb8a45e8bcd90052e37c443ead6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trivy@sha256:5f6eb1c4f61cb99c7fe3f961716c38006dea106c07ebbe90bc3af361ac6227af
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trivy@sha256:f68f70d976c9a0cd08b4b23a825d33cdb39e14563744ccad18fd53baa4a7afab
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trivy@sha256:7eb5cee73bce95773ebb439ec402b54f255226287498880836a4aaf1c2ce0f11
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trivy@sha256:c2b482caa3db7891575c8eed0cd8325e6171152f864097dd37cdf8105d93c277
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trivy@sha256:eb292d2ff691e7b59e27ea3818bf582533973f02e511a7a1c23529fcca31a407
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trivy@sha256:4085010bd61e765a3558418f75f64fe49dafac1e1122a5a791d69e1dd4a1419b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trivy@sha256:5f853fad9f6a08bb8ad3e6395c9ecbde91d990ad012ecc2f60fd6b249b4601e4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trivy@sha256:d3f97686f0a82c9b1a7ba75ea7d978c810aa88a176b38f3125811549d485a1db
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trivy@sha256:83fd0534c00b1cc615d0c319739c88880e6e5801ff2be25dabc9c7cb33829413