Sign inSign up
clamav

dhi.io/clamav

ClamAV 1.5.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.5, 1.5-debian, 1.5-debian13, 1.5.4, 1.5.4-debian, 1.5.4-debian13

Index digest:

sha256:681018bf364940cd643205de7696b73aecaec3f568deddd8d5acbd0f3c50546d

Manifest digest:

sha256:852208260170dc07e521e7a38fd95ec86101c4c7830263bdf162d901b467073b

Size

145.41 MB

Last pushed

14 hours ago

Vulnerabilities

0
1
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clamav:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clamav:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clamav@sha256:77b2ad8a36dee05ecdf6e5bd9ed39b70f3d023a169d6866040cf166aa77f04ce
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clamav@sha256:6354689342b882e7128f0b38e85d0c6931f87e753df29b35b7f4f79aa8a29d9a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clamav@sha256:83f3519fe6c039c108d8b146e5408c2d5154ad8eaff07d5b11fc51a2308657ab
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clamav@sha256:332f5c9d6e4a81ad7e51fecb377b58cc8571ce7850c95ed3b70e7b2bb3fbba27
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clamav@sha256:e1468eecaf75a5d8ddf91b429ffd3b48023f91acfc3e0cc4513d92c11aa051d1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clamav@sha256:f25a63df9610b4b462d6b50b9138f2738687a9db54f3ef0efddb68cd19289717
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clamav@sha256:9af532e36ac7736fb9bef91b71ed49ffdf32f6622d2694bebd52739fa666dea8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clamav@sha256:9d34226277c4c1c2b17baf3ae821ec9a776b1727061440652f1df0ceed0790a8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clamav@sha256:a76d1efcd73ba3d9a71135333b681d7955272cc91648aa1e3f0dde5c747b1d24
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clamav@sha256:81124bfaeb005af97ca19a29fd0698e4c4346ec70142ba86b360f50fdcfa55c1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clamav@sha256:6c8c6292b110f726451299d29d8e2f70ad36142f7c157bdba3f47cc24f7c7802
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clamav@sha256:621aba5ba7d7d71e688b495eb751a7641c960000eb139aa1cd53949e84bd4569
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clamav@sha256:d486cdedde56cda9eb0585eb30af65485060cba0b05c29de5766c4c93cb70bee
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clamav@sha256:ab7f5b14a371b0293185a1093c6bedeb5da10967d96767fc9df4fd1ba16b350a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clamav@sha256:bfaea39d7602fded99019938e823336291ac314c084964b276b7c8e5f4f7dfcb