Sign inSign up
clamav

dhi.io/clamav

ClamAV 1.4.x

CIS
linux/amd64
debian 13
Tags:

1.4, 1.4-debian, 1.4-debian13, 1.4.6, 1.4.6-debian, 1.4.6-debian13

Index digest:

sha256:4580bfc71afdcc923ba539fc0b2c4c1c492a10d5abd481d1cd9e332380c79416

Manifest digest:

sha256:2592fdcd2c9266cb774724e0d6bab8315df66b4a278748fa705f9746159d867b

Size

143.61 MB

Last pushed

4 days ago

Vulnerabilities

0
0
1
0
0

Support

Active until Aug 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clamav:1.4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clamav:1.4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clamav@sha256:616e541ded52c526186e2e7638803cf2d90e60b8210c8b7c648e51ad418c11df
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clamav@sha256:7430240c4e86f18c8b916781bff3ae376254395844ebc046fd8cd5ff02d23be0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clamav@sha256:b4857cee3d92211f4eba57e6e8d6240c8aceb33692e8730f964f6bf5dbf267fe
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clamav@sha256:199f321eb27fad10eae6f8ab581149ba61feabeb848b7961ff6c62ac2a611cb8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clamav@sha256:aefbc067e29e4862b1ecdb6a0503b423de6c92bb68203dba64e119e9cb8782e4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clamav@sha256:70df01b230eb92cf54301236908dc593f49b6f7d285337c9901cf771544439bb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clamav@sha256:dae4edbaf85282330545a0fceba8c6da1e175ff578897aea4357273279cc6168
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clamav@sha256:8a1266a88da48a7431b87b775256d78efe6924e6839a321c327a6e986e8a2585
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clamav@sha256:26e2c4abb8fe8090e35748fb73b9eb4eec456349cf39ecabf8de87e8f0cbb540
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clamav@sha256:2e7ecbaf61855df2023a57a0aae5308a780d73f35db47e1bc9b408a5ad2a4f37
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clamav@sha256:39043f3c66814c13409f4d6a1dcb64f8b03bcad072f674bff2948bf57316a9b2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clamav@sha256:03215bf26f638ea274b6e64cfd6180eefe9d14cf64b38cd4632828c525bd0a3d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clamav@sha256:67bdc96d8cf7144b7f2f9d7ebd031cc641ff6e98bbae25775990d85f32b330bd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clamav@sha256:3e65cc3d09f6261cc1f24f8f59db6b2f138e78905905b5ebd3d279238402dd47
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clamav@sha256:e5d46f89a28a8041578bcfbfe4877fa5abc57f9b96c0ce16261e0f10ab24efae