Sign inSign up
Trivy

dhi.io/trivy

Trivy 0.x

CIS
linux/amd64
debian 13
Tags:

0, 0-debian, 0-debian13, 0.74, 0.74-debian, 0.74-debian13, 0.74.0, 0.74.0-debian, 0.74.0-debian13

Index digest:

sha256:eaab7362d6a64aef30158d19eeeb5568a03a361135a8600d7b73c12c4eadbe61

Manifest digest:

sha256:db666d33cb95930e3932439e7a4c3678f480ea033b6bf1ffb6b7228d9e879d3d

Size

43.30 MB

Last pushed

12 days ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trivy:0

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trivy:0 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trivy@sha256:0e61b524fcfa74b3eb9954c20fd14e6699b34bcfb5e1e95d067b0b33c49856fb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trivy@sha256:d56eba97672bef474c1656c02f2696a8c8ef3a8ee9078af60e788abbfca8b37f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trivy@sha256:d8754abadde36a2acd806315baf35de31718ae5e1a8530a1d548e3ff9c6b869e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trivy@sha256:bf8c12eb451b8079af2962df752ff83eb70e60d0020ab74590ad7e8b658688f6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trivy@sha256:dca2857655c7254455c07fe819d584514c1345c8f3643679f7041f7af75b978d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trivy@sha256:6d58684db7800a65903302ade8e19a956b78045db613f622dd08eb8974e96788
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trivy@sha256:3c7f4e71016ba84e333723aab4cfa3aa0e649987d33c271b0f1a49e86b2dfa9f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trivy@sha256:d8e9b1c4642eb66581c7529e7c34d7df9a03122ec16758a0191c385a802f6bd4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trivy@sha256:9a508cba97061d46e30717ebd9f018bf1fb483ae336c89c1429a6f4ae7581007
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trivy@sha256:9ad6bf9526d40ad7b6f675da3755293bc07ed818a382e45e0fbcd9549a858bae
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trivy@sha256:3fa18d924407c4d9c6e23acefc51313e235905cc71da8cf68132d9903431269e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trivy@sha256:be84d8b5dd3586e0d4a01182ef6970384693b979ddfabc4ef56fff4def6c5853
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trivy@sha256:3239ead9a8ba56005e3cf1adb55ef652327736ebcc7685918155bc6761a7027b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trivy@sha256:4c08198edc68dde1c1e0818d4ebf6897815d66a632b59c1e3bf3ba381bc2f12e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trivy@sha256:57c5e22450d5c6ea8bd6211b04085968daafd1d169d37f2e13188ab137f210d2