Sign inSign up
Trivy

dhi.io/trivy

Trivy 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

0-alpine-fips-dev, 0-alpine3.24-fips-dev, 0.74-alpine-fips-dev, 0.74-alpine3.24-fips-dev, 0.74.0-alpine-fips-dev, 0.74.0-alpine3.24-fips-dev

Index digest:

sha256:4ec299773113ab0013b6021849c2ea0fc2f7275fdc2f1c4a08ca51c1fd2eda61

Manifest digest:

sha256:bc8a1f986fb3373a8de1fadada717d926ceb8ed4e4d709d9405c5c796be9c593

Size

87.86 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trivy:0-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trivy:0-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trivy@sha256:0f0887883baa4a74f1d71aa177c0c0d22458c2fdcea2e1d3f1bf459a03c24ce8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trivy@sha256:e7956ee09836de6f49ad05f3d23e32218d6349c11f469d5bdf9b902fb457b76c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/trivy@sha256:7f700db64b79d705b74d1223c86c7ac7ad626bd19b8f51db784fb633003c95b5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trivy@sha256:9028543350e8ccba4d28e2612db2e9a7d350481252e6aabfeffdb91518b56afd
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/trivy@sha256:a2b74bdef88ee7edc8fc571685391a62a20a77a5eaa7879c9be14881687e2ae2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trivy@sha256:fe0b99b5d219962da46825d37fbf3ff3ef2cf2783d289199b40b866b6d7b5bfb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trivy@sha256:fee36703652591f619388935383f0188d951003cb6babff0fdd47313eaf9e329
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trivy@sha256:812b5291f3e8c5b4c04ea0767bdfd5453d2ba83ef448d57a1b153c40129d50a4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trivy@sha256:7944ba9f381773908cc737c3803d19d7d41304750d215e234b8fd0a56dabc216
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trivy@sha256:87fa563b40c0d173f147c21118bd3004315f047645e5c4f02fe163e900081811
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trivy@sha256:3fd653c3d4dc751c9459ab9b4e78358729a37c030cf41aa47cca1c9f5bae4cda
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trivy@sha256:a032686eb19a321c8076e1c4a474c79e00d039eb5f7ceb1d96b10a0e9bda0e8f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trivy@sha256:58650dea51f8f0386bac6a147568ea199a19e417da0a90d72588cd721c51da3e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trivy@sha256:1c743b6b2bb124d7d2aa349e5a2bb10c8af8cd38c142817404e1274a88eec351
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trivy@sha256:74982eddbf4a090edd1b802ecb1705123d1a6022554e5d87527ebe39a018bb11
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trivy@sha256:5620dad00a13a54d71450cb357eac0ecd26a4c26eb683bd99dd8f1c76d0f733d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trivy@sha256:4c99a0b5344a01972b0348cf577880c5da15b5b053b55b1ac76ce9fed9f4bcc0