Sign inSign up
Harbor Trivy Adapter

dhi.io/harbor-trivy-adapter

Harbor Trivy Adapter 2.15.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.15, 2.15-debian, 2.15-debian13, 2.15.2, 2.15.2-debian, 2.15.2-debian13

Index digest:

sha256:57b7af32f293ebaf39205cc12fba2ff6ef11d677cf4815df91e7486209e58db7

Manifest digest:

sha256:74f7908be12bb27daf3631eff8bfc2e742b54cf54a124fccd905fb004faa12fe

Size

55.37 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-trivy-adapter:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-trivy-adapter:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-trivy-adapter@sha256:7a7118f4da558df8fdea2e0a5153f225cbd491566675b5b25b6cc0213c2670d8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-trivy-adapter@sha256:c50c2ec3b23bdd1edf61af9ab9ac2ea110c35616251615bb21e68261e2ddee8a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-trivy-adapter@sha256:4b99b78e5d681b990bda52563488cf1ea7c13bdfd9e61c6d12651e8ba99b0f2e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-trivy-adapter@sha256:17f3a10d95696787493da58237934a9dd9f17ac2b9c64bb7e8415650da53051d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-trivy-adapter@sha256:4b7b26c040a235cf8c7472c06e926cc6fd37fd2257081e87dc1c7f1efe7d4030
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-trivy-adapter@sha256:269d73bdd4ede1faae7489c6ad739145aedf34d752fdd03fc4c38b8c4dd8c6dd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-trivy-adapter@sha256:dd49767a7c3b16ebad03cbce289afd88d27e122027ff834f8d714f419d994d51
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-trivy-adapter@sha256:db7ab5d7fb0f272182e859d0cb6883cabbe8e6113e51f16b3fe8555c246b6cc4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-trivy-adapter@sha256:b38294a95ce698bc3758827627de8d93dc216d65682c1c22d03a1c3daf2bc202
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-trivy-adapter@sha256:bac51c440c88521e92b925cbe1b05097d217708f9a0c68c544fa8b578408d8db
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-trivy-adapter@sha256:d43e7b774ad3e15e6fdf629f38ac8145a22f57a8c9ff9af238fcaa82df2efa83
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-trivy-adapter@sha256:2d822874f39e22581c8a750d28f6422ba0a540b376a9cb40ca64286fd4f1783a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-trivy-adapter@sha256:54125b4b99f1dac7c025d30e0524ff725c6119f459febc6aef12c1ab87da7d04
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-trivy-adapter@sha256:72d2379dd4a6f82ba17d20260fbda157507f12ea90e3699fa8f07a777f27d28a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-trivy-adapter@sha256:e9e69b17f7f9f57b0e045b3017e756820149ada01036ea70d28a4eb21539a54c