dhi.io/trivy
0, 0-debian, 0-debian13, 0.74, 0.74-debian, 0.74-debian13, 0.74.0, 0.74.0-debian, 0.74.0-debian13
sha256:697c5ad2159bd81f5e17bfa7493675933c1b8fd5c119a3c82bd9aaeb37b4e3ef
Manifest digest:sha256:95d1fc785346461b5ff9152bbd9682a99c2b3e420e3195a55176cf63e67fc95f
Size
43.46 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/trivy:02. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/trivy:0 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/trivy@sha256:8063db5601d72f83f73f9280ac62910c01886cf25c9052ad084ca7ca35075a55 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/trivy@sha256:04db8ea8cdf6b4854695f37cf7bf8e3cd250b00e18276e3f53d4ecf8c6ff19d2 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/trivy@sha256:c5dd79ca8e0c4ad9c5e03c1f6999e62a94584bcc613e1de463eb8e49474996e8 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/trivy@sha256:a98df11bb8ebd2cf28492eacfd1f91c438aa0a4a117243d7fb43daf2c1851957 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/trivy@sha256:c88433edf015a6d28bb405ed4a840d96008eeac610bb4ec27987ca1899db7edf |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/trivy@sha256:c4dce1d3c20589ab7900cc296193d461c072d0c26674baad5a47fdbca47f991b |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/trivy@sha256:6dd4fb84c9c137512d5354608ae99fc82214bb2b5e01b7e1898fc8f3f1da477c |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/trivy@sha256:c41ea7cd5c2b98f22e731f828f066fffe53d6d1b125f5bbec066366e6a277021 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/trivy@sha256:3bd044cadfa6dd7b3dae38bd783f8c1af12711ef38caa2aa4b21b9dc75ca8f66 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/trivy@sha256:ef5fe1a1810b92eef78e681ec12a2a8df15f6fe1ffb9ca7dad13fc6e0bf30bf6 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/trivy@sha256:b9e7206e628b700d80321eecf338abb16eca927a79492abc96c5fdd5bdaef06b |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/trivy@sha256:9d348f4c4132bb3757671433f596678414093f836df54b6469b2692e2cdd03bd |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/trivy@sha256:03865f447a7054e074af8203b21c38c013932c1e6ce7b80722873a679ba4489a |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/trivy@sha256:3cb20f2dd2a8a618d86a5739526b9861d9f4b36538b01ee7b686459056f74d37 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/trivy@sha256:9c0bdc6ca8ec8ddf1a9a9390fb858a16feb545050c32e5512fbdc10b4b86f88d |