Sign inSign up
Harbor Trivy Adapter

dhi.io/harbor-trivy-adapter

Harbor Trivy Adapter 2.14.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.14-debian-dev, 2.14-debian13-dev, 2.14-dev, 2.14.4-debian-dev, 2.14.4-debian13-dev, 2.14.4-dev

Index digest:

sha256:94570544ed4cc5a16b24fd090082c52a6b8bf8b66ad3ea4bd6f3f9c35857d85f

Manifest digest:

sha256:abf5778bb8a18898fd6b5db9c7900cb1bade2e7decfd4c243645de751d83a33d

Size

74.09 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-trivy-adapter:2.14-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-trivy-adapter:2.14-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-trivy-adapter@sha256:69a99883682ee0b3b7a42102c42e4af40ac8b15f7a9991f80e4de1fc7683c060
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-trivy-adapter@sha256:1df1fa65e4906c4c4c6fec7ce947219b8c499ea06bc39b6b088430143cbbfdde
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-trivy-adapter@sha256:3919bfd58c9b023ed3e7c673b068d2fc03c94366829a708bec56af64a0c5194d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-trivy-adapter@sha256:d4e27eb08e1dab47efc21dc10a772e5b75ca8c7fe140be97525f79841c54daf3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-trivy-adapter@sha256:a32307f139ee3bc1a944ee30f597df462ce1f1875c11796fa85481e6fa33cd17
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-trivy-adapter@sha256:161293b44a6da2962b1ba829b40e65bd8fd3b553ea232a41e636d6e88b68e640
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-trivy-adapter@sha256:f7032959fc295ed4d4602db421c78f7cdbda4c03540ebece7f255f17826c844f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-trivy-adapter@sha256:97de7825257285c1bc8daca9eba1eabe0b39dce8e3d4edbe4879c989f2c1cae7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-trivy-adapter@sha256:e11c98ad6542ab490fe91014ac19d2533a90ef84e388d3e9158cb5c5ea132c6b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-trivy-adapter@sha256:3ab5e506982e79023dc99722228a40f55cca9e729ba7adf38fdbe4815c1dc54e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-trivy-adapter@sha256:a05e01db3a2a59e728ecee045acf43ad23cbde233751e584dafa210efbb15f6b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-trivy-adapter@sha256:40d3e2c7a2a9b5aedec3a27f464bc3c88333b8526fca48a7ab74368ee66b67f2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-trivy-adapter@sha256:7255ef0d0a602359b7641a4244f454f5ea2c8c906b389e188ab1d689cfdc2ee8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-trivy-adapter@sha256:2a0f4212b68447d42907f78f16129d6d2f8a92e2ba2190c26daf6b769e0bd05c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-trivy-adapter@sha256:8069b84e0d819f100dff96e33c47b646cb038d1f07e22e05a21dea221780ef46