Sign inSign up
Trivy

dhi.io/trivy

Trivy 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.74-debian-dev, 0.74-debian13-dev, 0.74-dev, 0.74.0-debian-dev, 0.74.0-debian13-dev, 0.74.0-dev

Index digest:

sha256:a31770bb38cd3e6300e35553f407fc720706f2f956186610fe04a8ea27ad9f4f

Manifest digest:

sha256:3d32d54c175b81bbd0fd78af0f648b46c4578be623b6d55ceb76ba1d467c443d

Size

106.42 MB

Last pushed

51 minutes ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trivy:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trivy:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trivy@sha256:306bd398aebce242f2b13fc9e5fac2d826fe0f6bf572bbab0184eb4e93c2680a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trivy@sha256:6aaf670533c7f4d5909ad1eda9845b524d62cc218fb79aea82d6c5066845ad31
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trivy@sha256:019efd7ed6a28e77f11e9cabd6b5fa0d3790e14016ea3ad016d2f71729edf66f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trivy@sha256:04b8597099033d4bf315c4d92298d40ccc8422736e60c96f6673cbfcc0959bbf
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trivy@sha256:6881ba4a0694867e4f1cb7757c23c5aba4f3de8d1ca98c0334cc4851e87a1083
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trivy@sha256:28cc5e68c4b5d86ed35adc8b9ff88eee36afb5b4c45483b8abdaed2541c24352
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trivy@sha256:2fab0dd1569094bb9786c47fb1d4b574142dc3068bbd2bd6086594f491b1d928
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trivy@sha256:9512764431551ca1392782954a02608c1e6fbf491777557a9c7995b1e33f1bc5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trivy@sha256:f8bf8a66fec153f0d79727278df145f4a5c61b54d1b24dddcb835264edd929a5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trivy@sha256:afbce2bff335abe59ec29c01b7c5106540b1ec286c6b08d666c407222865e9dd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trivy@sha256:4fbbe0d3ab24c1955cc4ff1c905ee56dcf77697bdf4b85c3d279cbd66dcaa596
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trivy@sha256:8177ef8ea58ec7101b97b8012f86a0e3f30076774d9a6f405c0da61fecbe502e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trivy@sha256:1e44ea2de511cebfd5c42b70f6d907a967dd306cf9f6783ab14f1b8cbba1efa4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trivy@sha256:ec140c9cf7a430ec925808cd3e4e21b2c07e96a8df3c9d8c9fe758a34dbee84c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trivy@sha256:7f11316292842beda18d595e40cbe77dcb9f73ae7dad3e01f016a1b6f83b7188