Sign inSign up
Trivy

dhi.io/trivy

Trivy 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips-dev, 0-debian13-fips-dev, 0-fips-dev, 0.74-debian-fips-dev, 0.74-debian13-fips-dev, 0.74-fips-dev, 0.74.0-debian-fips-dev, 0.74.0-debian13-fips-dev, 0.74.0-fips-dev

Index digest:

sha256:479e6fa0ed6840693884c48a8ccbff4e7314bf99a9616e0f0be3f3fb1be21baf

Manifest digest:

sha256:d827a854e8047d3ffc2917638bc35a4c56e57666e08ca7eec8327df7355a48af

Size

107.22 MB

Last pushed

5 hours ago

Vulnerabilities

2
8
1
2
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trivy:0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trivy:0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trivy@sha256:7c6c3efab84bfe518e93a642239a9e76c8b77a8df2495fc08559a5d4096b2e3e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trivy@sha256:682ae0c9c354c6147a0b1138d255eb4592cb46015acb6ada206ad317e75b3f23
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/trivy@sha256:18b54b8e64a0dafe57f5c4a8b6ab09933f50f74d5f663b10b381fd89af35bc6d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trivy@sha256:eee188199108402125fd2a4d65388023f34a2b981b4842f402218ee2b6fcdf30
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/trivy@sha256:37c42d2b4ca7406e8df0d26bb7ee702b39c52e42743259b3d588db3062d60bdd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trivy@sha256:b05a41019a202662cb7ad7288a5f4ffccbd9bc8f9579d2dc117c95630cab8706
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trivy@sha256:b569eefc429227490df4708bdca11838b48e9fc82d54a38c2b8120fd82e3fd6a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trivy@sha256:4b109c383faf77a41d039cb8be0363b68e15f5146b38fe404b2186563b234cab
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trivy@sha256:800b5266166d4ebbc6b94d568f044439f8457ebe0c1e495b5002a17c123ecb41
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trivy@sha256:74345256dfad8c5ed43d1afdc276296d00404d354141197794b92fd44193c086
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trivy@sha256:c72574ddc54d5b7323ab42b39a77c97269cd0772fb704d99e0ad71924b0ff977
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trivy@sha256:1761b8010109aca8eac9179df88df9b452c7d1919a001be53b52c830de46e3df
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trivy@sha256:cc6271b350f7bc0ab44d4b6b784b198f6dea5ae9e8e3b79f98d0c12aa3ba4735
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trivy@sha256:f8c1c94eeaff22ed26970389f040d35a590be404e45f67eac4a0e840bc690785
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trivy@sha256:9f7039fbe12731088f80c2f98d27d57a5d40c8f421bdf66994d9b5ad22eda953
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trivy@sha256:f9a8f90cc64f2529e257e5454f3386be6bc68e684f52a504d98d7ba49a0fe822
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trivy@sha256:e5a13acb622a9398c3c2bfbd47b5bd22562854dc50e6f6f4a0ca4f0fec102f3c