Sign inSign up
Trivy

dhi.io/trivy

Trivy 0.x

CIS
linux/amd64
debian 13
Tags:

0, 0-debian, 0-debian13, 0.74, 0.74-debian, 0.74-debian13, 0.74.0, 0.74.0-debian, 0.74.0-debian13

Index digest:

sha256:697c5ad2159bd81f5e17bfa7493675933c1b8fd5c119a3c82bd9aaeb37b4e3ef

Manifest digest:

sha256:95d1fc785346461b5ff9152bbd9682a99c2b3e420e3195a55176cf63e67fc95f

Size

43.46 MB

Last pushed

6 hours ago

Vulnerabilities

2
8
1
1
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trivy:0

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trivy:0 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trivy@sha256:8063db5601d72f83f73f9280ac62910c01886cf25c9052ad084ca7ca35075a55
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trivy@sha256:04db8ea8cdf6b4854695f37cf7bf8e3cd250b00e18276e3f53d4ecf8c6ff19d2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trivy@sha256:c5dd79ca8e0c4ad9c5e03c1f6999e62a94584bcc613e1de463eb8e49474996e8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trivy@sha256:a98df11bb8ebd2cf28492eacfd1f91c438aa0a4a117243d7fb43daf2c1851957
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trivy@sha256:c88433edf015a6d28bb405ed4a840d96008eeac610bb4ec27987ca1899db7edf
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trivy@sha256:c4dce1d3c20589ab7900cc296193d461c072d0c26674baad5a47fdbca47f991b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trivy@sha256:6dd4fb84c9c137512d5354608ae99fc82214bb2b5e01b7e1898fc8f3f1da477c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trivy@sha256:c41ea7cd5c2b98f22e731f828f066fffe53d6d1b125f5bbec066366e6a277021
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trivy@sha256:3bd044cadfa6dd7b3dae38bd783f8c1af12711ef38caa2aa4b21b9dc75ca8f66
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trivy@sha256:ef5fe1a1810b92eef78e681ec12a2a8df15f6fe1ffb9ca7dad13fc6e0bf30bf6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trivy@sha256:b9e7206e628b700d80321eecf338abb16eca927a79492abc96c5fdd5bdaef06b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trivy@sha256:9d348f4c4132bb3757671433f596678414093f836df54b6469b2692e2cdd03bd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trivy@sha256:03865f447a7054e074af8203b21c38c013932c1e6ce7b80722873a679ba4489a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trivy@sha256:3cb20f2dd2a8a618d86a5739526b9861d9f4b36538b01ee7b686459056f74d37
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trivy@sha256:9c0bdc6ca8ec8ddf1a9a9390fb858a16feb545050c32e5512fbdc10b4b86f88d