Sign inSign up
Trivy

dhi.io/trivy

Trivy 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips-dev, 0-debian13-fips-dev, 0-fips-dev, 0.74-debian-fips-dev, 0.74-debian13-fips-dev, 0.74-fips-dev, 0.74.0-debian-fips-dev, 0.74.0-debian13-fips-dev, 0.74.0-fips-dev

Index digest:

sha256:c4e01e0e0385f7fe1ee2a1ff4699db0389d54cd88a963a55b5f2db946bf2bcd9

Manifest digest:

sha256:9bc61ab9fabe65e3cc8567cf5ce59873140f8f260794b75f0d5acfab7a2b5edb

Size

107.22 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
1
2
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trivy:0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trivy:0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trivy@sha256:5b95d8997808533d258b25f839bd9a2797a41de38b2a16d74ea48adc79d9b6f2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trivy@sha256:6d25c32013ca9d662403508a845a246a5971921f2ab8c392de84654c18d212da
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/trivy@sha256:cb8de2c3b9c2bdf779e35ecb3653b5e3c2dc96a07c4f1a048105e79f75fc4b34
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trivy@sha256:aaf6db6d54d5739495435fbadfcd1c640b1757806ea1f2fc1ef61540d3a55726
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/trivy@sha256:e420c55d357af085c716849cda5d3d1160453ff671faf82c2d23d6502d3b5965
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trivy@sha256:fa3110b53009c3a088bf1b9d0d755b54dd7a07c16753c424faacc646abf25704
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trivy@sha256:14781ec75b9e379a00687d57d25beec0b1e2bc0580f0dfb2c38848e210bb64fc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trivy@sha256:e7deb2b45f3b4257c97b2facfbb96aefe44bd3fe5b6c688161d23e1084062f8e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trivy@sha256:a22b98e38ef597034aacf4cda192d051dc03adc532aefe4e94d67c95ec187862
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trivy@sha256:1dd4e685a8e4f943892baca81845c8c6d2dbe7a2be9793a3eaf79ac7cad46dc3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trivy@sha256:7679d98ab7a877d22a7d0e0e09f397802b3eec848d2f7b48d510ca30938528b4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trivy@sha256:91ab01ac7f5e6f6822b4d45afa27a17749a7aab8ed6a388d339d2e9b8652ce61
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trivy@sha256:a35f825bb7dfb582ba3a34a03d8c24b47b5c4afc09f5c41e04f400c31b2c5dde
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trivy@sha256:c481cc924abb27af72c941402fdc4c352deae3ec4afa5ee893a7f080d3183ee2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trivy@sha256:98e40ebc99fe6e318b44677ad9f9e3c22b6faa8d0907a149646be24bca57ad39
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trivy@sha256:efef74014535792146090fbd71f6d9b2fcc48c88d561298cdb1cbd0a419c671c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trivy@sha256:bf9dba466f87852837527a268b60a2d9fb29ba44ab47d2d8a659a340663cdf20