Sign inSign up
clamav

dhi.io/clamav

ClamAV 1.4.x

CIS
linux/amd64
debian 13
Tags:

1.4, 1.4-debian, 1.4-debian13, 1.4.6, 1.4.6-debian, 1.4.6-debian13

Index digest:

sha256:97e3f80427540ff5a057e6f592cc3ce95ea650b2859370d901d6fe36c6b12ff3

Manifest digest:

sha256:99c7810ebccf7cd366e997863057569a1394578a73d23abf00b793f49d7e657c

Size

143.62 MB

Last pushed

2 hours ago

Vulnerabilities

0
1
0
0
0

Support

Active until Aug 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clamav:1.4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clamav:1.4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clamav@sha256:1f4fec6edea83e0c79c37411d0fd826943c312bd99c54c480560cc67d76c7c1e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clamav@sha256:807d06772f705de45781cd65c388dedc011241439a691dda7915517ceac9dce7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clamav@sha256:578e8697db4002cdc6a7a48d9ea7639c70c66fc0409c5274a91303cbc870b9b4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clamav@sha256:1317c6303f3a56b6cfa3f298d802249578a4641fa1151bb613e1d980fb1bad4d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clamav@sha256:fd5a09cd23e2ad090039347f9617c3a021d003d2eefad1c1c7f792ca3789db26
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clamav@sha256:43d39abbbe7af1e11846c541d9778b3e70e86194564eade7dcba0ea7f31f7ef4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clamav@sha256:d294c830d2e096cf7ec1ca99b5bb9c550ac9faa70ba8aa1f61c8ee64a1af2647
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clamav@sha256:c046c7cf83633929c65126e0b9a59d47032f5e13647c8e8599e157c00f3c62f5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clamav@sha256:3a543355140efce6c40e40d0d99737cb2bca427d3afae71bb4dd38462924f5ab
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clamav@sha256:03bb217f1c2d9f5bb52da740e2ca9b31d94010844e7841c88e8dc8069de125e9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clamav@sha256:6baff6435cf7cba5c07b26c0dae0d5b06e197634df0174d8a4bd57744fd03cad
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clamav@sha256:e2b5f2f8e6ad78e1cc8b448433857584b3700f9526d416f4e390a6c30bc460b0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clamav@sha256:60ee3281f78d6f474b4f2e5be3d9ba4a9fee1e3371396396caeb029c6208e544
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clamav@sha256:512ee3a8c68b50f24b5f30f9f8610ecd33476ed2a845123a7a03ca0f3c42481e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clamav@sha256:a91ae39e8bb058b89dfa4c2ae320958e1bde4ba0152e166300ad1de58b8c55f3