Sign inSign up
Harbor Trivy Adapter

dhi.io/harbor-trivy-adapter

Harbor Trivy Adapter 2.12.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.12-debian-fips, 2.12-debian13-fips, 2.12-fips, 2.12.4-debian-fips, 2.12.4-debian13-fips, 2.12.4-fips

Index digest:

sha256:cd78ccd2906d9ff2109270aa5368565f6b82483b5d689d5376256e2e26123661

Manifest digest:

sha256:dc6b62572f5feaa7027c1f6d1d5547caa48b0c050d664c8def852abb98046161

Size

55.74 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-trivy-adapter:2.12-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-trivy-adapter:2.12-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-trivy-adapter@sha256:8e5927546073d06bf42659a6fb867e572c61ea3b0507e60871f1b7ecb1464c5d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-trivy-adapter@sha256:086ae259254c295eb7b83a862eaf62b787bd7d55f9242bd5e639f4131888f5ed
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-trivy-adapter@sha256:b97e1753db2f1a9eb8870dc16aff7b3da5089b2723c14fb2839b0d45c1e8c3c5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-trivy-adapter@sha256:06a102281ae24c869dcd0ddb68eb11701a93c7e3c07fd5b7492ee4c7ee40950c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-trivy-adapter@sha256:8c7e593efea46f11d187f832da059d7e33b6e472304d7e9fccf5b898ef098303
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-trivy-adapter@sha256:fd3ffe69f57496d91dda0b1275d41ff57418dde2897ea74d1bb6e7d71fe5614c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-trivy-adapter@sha256:69a70e80edea5f46f07335fd958c0201fc25e78bc0bf6925a610693b4afe87d8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-trivy-adapter@sha256:5a4a2ed41d202739475d086ce4eaad5decb2ff7e654e3a8da193d42b3a82207e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-trivy-adapter@sha256:87db35f3de7f5f536882c7c581b19569fa299d398a393a4122329c037192e10f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-trivy-adapter@sha256:50ca5538c69da4979e65fa173ecda28238586357c8ffe8d0dcbe89ff4198af7c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-trivy-adapter@sha256:f53739861dccf0ff9eb7e2e5ca71b2311834ae14ae6cfd3e8c9d467fc2b2a61b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-trivy-adapter@sha256:e4c373ce9ae8f98bc7041348c8e776c2e152f7a9b363efc975714527c9752a4c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-trivy-adapter@sha256:5527fd16882ea1279d9076b1bc93f12d531fe5306c0de5e254cdf34914f86f94
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-trivy-adapter@sha256:e909a7080bfd12458bfd9d5230e052f69d95ee1ab0325ef1e70bf791c173ff4f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-trivy-adapter@sha256:42ce253a6e33a17e2d6526bbab8f35130ec39b325b17557f6c4d08a0da177ca9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-trivy-adapter@sha256:f2c628675334a65e7848ced3069352800ff2904344fc1b851d0c7326ba839908
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-trivy-adapter@sha256:96a7c6fb90a5e7eb186991ed1266c3af354b36ea52d18386e33f2a58df72fedf