Sign inSign up
Harbor Trivy Adapter

dhi.io/harbor-trivy-adapter

Harbor Trivy Adapter 2.14.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.14-debian-dev, 2.14-debian13-dev, 2.14-dev, 2.14.4-debian-dev, 2.14.4-debian13-dev, 2.14.4-dev

Index digest:

sha256:b96183417d97f96e5ca76dc5fb762293b5a9b9fe6b15abe7c6efc7b648e29819

Manifest digest:

sha256:002fdb614358c4bb9931ec74368d57f3d5d9adbcd0fd20612b61beb5b93f3866

Size

74.09 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-trivy-adapter:2.14-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-trivy-adapter:2.14-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-trivy-adapter@sha256:8f33c591dd1c757304af353036b9167ef7377a4c8db36a4ec5e7811cf4c9c3bd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-trivy-adapter@sha256:5f337c6e531a5078059aa8e39dda93a91df322f8f54346712a9738f4f2ac5a50
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-trivy-adapter@sha256:bde3b1bcf1fd4f7be2c550e832bc8300fd3549391b0597c74b4206df2d926f53
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-trivy-adapter@sha256:0cd2be9567cd00ccab3d122cfe46e840524fddd5e91ccd6dcf3c8b0ae2d565d3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-trivy-adapter@sha256:c4b34fcccd11f2c7154cc6ae4521969a3714e2d40b60b86de54974b3e497f700
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-trivy-adapter@sha256:a31e7067af5c0870652eef0e9ea555ee07db09a34891e56ae302dca5b3c66d62
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-trivy-adapter@sha256:c73f463c92004aa49db7ff8f0112cdcc830d1d478389ff45922566c0ab6d8ae0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-trivy-adapter@sha256:57208842671e14794f0069270bb8de8515437b9eba27127e90dd59756c2e9902
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-trivy-adapter@sha256:111a289cdc78604ad16d3e44024324490905aa7be5d32c50bbd1a17cbad586d0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-trivy-adapter@sha256:59539dfe7cf40ca996a8d694ff0d985ee6671ccee219d2b27bf99204687d1e26
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-trivy-adapter@sha256:b0e269b11dfb0cf5484500c56cae8459ce40f84f7418713b0ee570232bf35987
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-trivy-adapter@sha256:2ca018c4d643699d09e2fc591a92daddaa35182cb9088efcb7557a06dc04ed3d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-trivy-adapter@sha256:a8f009a91acf45fe2bc0ba05af72663f1d5cebba1a651cf554c6c99f371d7f9d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-trivy-adapter@sha256:e44368d86731096baf443d4520682bfd92627f4dd171879854dbdb82eb05b894
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-trivy-adapter@sha256:99f14cca680b7076f93ff6f1f045f7126375ae17e02027f43849eee6943fea37