Sign inSign up
Trivy

dhi.io/trivy

Trivy 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.74-debian-dev, 0.74-debian13-dev, 0.74-dev, 0.74.0-debian-dev, 0.74.0-debian13-dev, 0.74.0-dev

Index digest:

sha256:41cfc5c0a2a4e47230e7e9bbe2b06bf036e974c929c3ebd29082f5301ab6360b

Manifest digest:

sha256:ae2ce2005d9e81c5f1aa14ee6cafad573aaf8da3efdd6e7be8da3685d664e9c6

Size

106.42 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trivy:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trivy:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trivy@sha256:36bbe820f84605b7432750c2ef3de40e182eb6dbf5201508b1effc5add36e1d3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trivy@sha256:cdfcd71a110bded5113b83924656727e40c45690a90f631d3996cbe1f4b19524
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trivy@sha256:ea45f158d836d5cf130ffcff334092af2242fe66554df05b3292e3b2e98975c8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trivy@sha256:e13ee23a5600247cdba8cd4d101dfb3bbba874f35248438ded1af324c6d1f9a9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trivy@sha256:85abf2037d80c0f35b700c7f20614e26c0441c556c429427d74cf4b8ab60dc62
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trivy@sha256:fe921f12b710835037af54a2400440f04dccf43c2f1977fa393535ade20f8a74
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trivy@sha256:d07133f17d857517fa3b9179da424f5e704fc6f655c17ce1664d9f45107bdccb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trivy@sha256:f52ed16d39c533f3ca57e8f1d1fbe407ea68d4a3a28f3749de91292007d6cf61
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trivy@sha256:e9714644670a2a6a25aef43f44f0989959ec897efed20c365aeea5d492cb7b26
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trivy@sha256:a19be3046a752c287f6b311e0fc48d54efb428d6c02cdac2e1473323affa00e7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trivy@sha256:80260a618d1346c697853c4f33a1a09d7048a2b64237ff6d0c41eb37c644d280
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trivy@sha256:1094f8aeca2524fe0acfc37beb4ff0ad2ae58566f941aebf66316bd782c3d917
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trivy@sha256:5c383b668c89a02a7cc9179c5febba11601356652a311ad9d16ba15e07c91bd2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trivy@sha256:01eb5ae4b39f19f16b6a47fa368a9da18c9c8db3d72fc69488f318889a2778a3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trivy@sha256:7d21521d4350395e9b5505c72ef78f5a11aa35188d77d4eb36878b6154a69e3b