dhi.io/trivy
0-compat, 0-debian-compat, 0-debian13-compat, 0.74-compat, 0.74-debian-compat, 0.74-debian13-compat, 0.74.0-compat, 0.74.0-debian-compat, 0.74.0-debian13-compat
sha256:807b0a9ef722f52d6e5f7690030e40248e9a8b7c04b420daf3ab3c7c27fddfd8
Manifest digest:sha256:b3f354b7d6f844151e2b58b1f2e30391f9e814a21929bdf97f1ef9dd088beb8a
Size
53.81 MB
Last pushed
4 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/trivy:0-compat2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/trivy:0-compat --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/trivy@sha256:4211e1e25b202907a896f2b39d30aaa4cc1b35820adc751c48784bd661c1f710 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/trivy@sha256:98a9699a80442378c64a0893a38c3f0ada75c8d57a8db50a7089ecb4a232200c |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/trivy@sha256:30651ae6751ba3bbebb3df6d70d6e2b569739ecb5423f54b368aa0387ebd9d65 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/trivy@sha256:6fd185b0c6aa3a3d9b1863dd274599511a37abb788639d0fc1029611d34d37ad |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/trivy@sha256:226b78f415535226b8f440869e9294aacf4003aa48ca3e40852d0a75bc9798dd |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/trivy@sha256:7d02b05bcbf6ddde2ad050df13675386859ead3562ad36cca27f5d0523e8923b |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/trivy@sha256:f8399cb80d814a767817237f97d1e8f85db0e4b6fbd4a5a02d88df6b91b1663c |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/trivy@sha256:63edcf2fbd227783d78f13f402347603beaa7754fde966a960448e218ec4b2f6 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/trivy@sha256:d75652c8fc625d78d5d763ad17b661cf4c1f697c100e31a481fc5c839d1e1dd1 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/trivy@sha256:079cf00db5898b9762c6a0aa08cf064ac0b9a38ee702f5bcfb5201ec6344d4f3 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/trivy@sha256:ba0264bab6b33f59345083450bc8663fbd286062496efe4430f6d4c27dda88a7 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/trivy@sha256:9cc667d97e157c2ccdd6b9602a85b6d4fe58e9652cffa5b5c2982bd0d13f5beb |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/trivy@sha256:0255ceaec0e79e98bbc2e0a0363f86f4836b629a0aadb81b47bdd0ef0ca76bd8 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/trivy@sha256:8eb03acb90e9eaaf2c2f1ff6dc211622175000628a9b3486097fc9cfe8993ba1 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/trivy@sha256:e9603af1b7e211eb45aa7d23807da57f50f29001de74e4e09feb303a8944d5c4 |