dhi.io/trivy
0-alpine-fips-dev, 0-alpine3.24-fips-dev, 0.74-alpine-fips-dev, 0.74-alpine3.24-fips-dev, 0.74.0-alpine-fips-dev, 0.74.0-alpine3.24-fips-dev
sha256:1ce0c5d8a102816b789aac06e0fbb1d4f2c34d89f87e4e956e6845ac533c5634
Manifest digest:sha256:68b35bc15a0369e0e75d5855d3c11f4e7f9a1ceb5f8cd895c2745888aa8f512e
Size
87.57 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/trivy:0-alpine-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/trivy:0-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/trivy@sha256:d6ebe56902714c1a93c4321ea9ed48a521734c3572a4f0c875304bb1cd736204 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/trivy@sha256:3cda1bf9fdc4f9f31260328bc26e6f43c60274164e44d8572ec63b3db226944c |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/trivy@sha256:def985782a61f6fb288a0ac4c53818c36966fd8a4593e310b0c7fc05ca5cc2e3 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/trivy@sha256:018e25469d4eb70e64f0331fd32447033b974930cb0f76f287cfebd0e44bfa02 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/trivy@sha256:d6d704df6b83e87b6993eec5049190c31fd0545e8e3bbdf93ce32a1b05aae432 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/trivy@sha256:1cef6cfd1154ef4a6e4560c0d4a979ef3571eb1f428dd2a12f9c59b95f2d46c5 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/trivy@sha256:75c7aeeb4f006172f00db2a35f9a37090acc63d7b7b909c7c4fddbba647167bd |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/trivy@sha256:ef0c41e73b278bd560f72ca68781e9333114eeb8a45e8bcd90052e37c443ead6 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/trivy@sha256:5f6eb1c4f61cb99c7fe3f961716c38006dea106c07ebbe90bc3af361ac6227af |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/trivy@sha256:f68f70d976c9a0cd08b4b23a825d33cdb39e14563744ccad18fd53baa4a7afab |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/trivy@sha256:7eb5cee73bce95773ebb439ec402b54f255226287498880836a4aaf1c2ce0f11 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/trivy@sha256:c2b482caa3db7891575c8eed0cd8325e6171152f864097dd37cdf8105d93c277 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/trivy@sha256:eb292d2ff691e7b59e27ea3818bf582533973f02e511a7a1c23529fcca31a407 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/trivy@sha256:4085010bd61e765a3558418f75f64fe49dafac1e1122a5a791d69e1dd4a1419b |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/trivy@sha256:5f853fad9f6a08bb8ad3e6395c9ecbde91d990ad012ecc2f60fd6b249b4601e4 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/trivy@sha256:d3f97686f0a82c9b1a7ba75ea7d978c810aa88a176b38f3125811549d485a1db |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/trivy@sha256:83fd0534c00b1cc615d0c319739c88880e6e5801ff2be25dabc9c7cb33829413 |