Sign inSign up
Harbor Trivy Adapter

dhi.io/harbor-trivy-adapter

Harbor Trivy Adapter 2.13.x

CIS
linux/amd64
debian 13
Tags:

2.13, 2.13-debian, 2.13-debian13, 2.13.5, 2.13.5-debian, 2.13.5-debian13

Index digest:

sha256:f5fbf0318e3b186f9401fd7dd266ce63564d4c7dff64faec3fa743720f305ae8

Manifest digest:

sha256:ae1f29ec4212b3c6b12aa6f8ce811b7979fb85be102187c6dd108cf74811e3b6

Size

55.20 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-trivy-adapter:2.13

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-trivy-adapter:2.13 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-trivy-adapter@sha256:5eadfe27364e353b9bfd99d9345597a2bfda892d479241e12685329ecba40ed8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-trivy-adapter@sha256:fb93c5ecc5fa3d98a2d431de16a2ebdbb6ece5a31b234145220b456b710a9473
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-trivy-adapter@sha256:0cf24053e4d426b8e3e43642db2b9e56411b80aac2b61b8159484d2e683a4230
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-trivy-adapter@sha256:c7866bbaf9c92e19f85eb9b3a649456fdb8bd809ae7a35730d73fa51cf033d08
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-trivy-adapter@sha256:a1902f85d3a4ecafba4e7928ef175e6782b4b994a422a9e51c4207783b75b130
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-trivy-adapter@sha256:058ffe5be0f79400de2f33206a042060b4d522423310ebf75f3383fad095a503
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-trivy-adapter@sha256:6151ff7d5e5d501f2f318a8eed6af6c1c118b3ce8fb7b9c9a1e72e30ae65aac9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-trivy-adapter@sha256:ac2211a3d2d27629017b67670966d611747c8b9dad2991c382933c982e4fa79a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-trivy-adapter@sha256:e68cd6d5ea6f0be92cee725358ce716207076b0832ce11fa26233a6a8ebe9b2a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-trivy-adapter@sha256:5f240117527cf9db50fbe52bb2b7d8500912167adf0b1120958c3240abca304f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-trivy-adapter@sha256:cc3d29f7ee90167e6a13537ab199ddbb15cf386c2f0e5facd0e0b7431a4b612d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-trivy-adapter@sha256:23c6aa62703836f78fc6b48ec70eb75b709a64a95f1e1430daf456c93fd4501b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-trivy-adapter@sha256:4a41b1b2270b70ad4180ce7eaf71fabacbfa623e38dae951a462d4a8e8c97338
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-trivy-adapter@sha256:3e7240f4a53dac902bb9023f52bf41e510fc473e21752df8a700455a6aefa131
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-trivy-adapter@sha256:e2f2d7d64ea74a243db04ed66290a0041691fc73d0caaf0c670371d5a9add6aa