dhi.io/trivy
0-debian-fips-dev, 0-debian13-fips-dev, 0-fips-dev, 0.74-debian-fips-dev, 0.74-debian13-fips-dev, 0.74-fips-dev, 0.74.0-debian-fips-dev, 0.74.0-debian13-fips-dev, 0.74.0-fips-dev
sha256:479e6fa0ed6840693884c48a8ccbff4e7314bf99a9616e0f0be3f3fb1be21baf
Manifest digest:sha256:d827a854e8047d3ffc2917638bc35a4c56e57666e08ca7eec8327df7355a48af
Size
107.22 MB
Last pushed
5 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/trivy:0-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/trivy:0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/trivy@sha256:7c6c3efab84bfe518e93a642239a9e76c8b77a8df2495fc08559a5d4096b2e3e |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/trivy@sha256:682ae0c9c354c6147a0b1138d255eb4592cb46015acb6ada206ad317e75b3f23 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/trivy@sha256:18b54b8e64a0dafe57f5c4a8b6ab09933f50f74d5f663b10b381fd89af35bc6d |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/trivy@sha256:eee188199108402125fd2a4d65388023f34a2b981b4842f402218ee2b6fcdf30 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/trivy@sha256:37c42d2b4ca7406e8df0d26bb7ee702b39c52e42743259b3d588db3062d60bdd |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/trivy@sha256:b05a41019a202662cb7ad7288a5f4ffccbd9bc8f9579d2dc117c95630cab8706 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/trivy@sha256:b569eefc429227490df4708bdca11838b48e9fc82d54a38c2b8120fd82e3fd6a |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/trivy@sha256:4b109c383faf77a41d039cb8be0363b68e15f5146b38fe404b2186563b234cab |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/trivy@sha256:800b5266166d4ebbc6b94d568f044439f8457ebe0c1e495b5002a17c123ecb41 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/trivy@sha256:74345256dfad8c5ed43d1afdc276296d00404d354141197794b92fd44193c086 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/trivy@sha256:c72574ddc54d5b7323ab42b39a77c97269cd0772fb704d99e0ad71924b0ff977 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/trivy@sha256:1761b8010109aca8eac9179df88df9b452c7d1919a001be53b52c830de46e3df |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/trivy@sha256:cc6271b350f7bc0ab44d4b6b784b198f6dea5ae9e8e3b79f98d0c12aa3ba4735 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/trivy@sha256:f8c1c94eeaff22ed26970389f040d35a590be404e45f67eac4a0e840bc690785 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/trivy@sha256:9f7039fbe12731088f80c2f98d27d57a5d40c8f421bdf66994d9b5ad22eda953 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/trivy@sha256:f9a8f90cc64f2529e257e5454f3386be6bc68e684f52a504d98d7ba49a0fe822 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/trivy@sha256:e5a13acb622a9398c3c2bfbd47b5bd22562854dc50e6f6f4a0ca4f0fec102f3c |