dhi.io/trivy-operator
0, 0-debian, 0-debian13, 0.31, 0.31-debian, 0.31-debian13, 0.31.1, 0.31.1-debian, 0.31.1-debian13
sha256:ab776a6301cc0abff57d715c7457050510a6d09e2c86a359182a8ef82f5075e0
Manifest digest:sha256:06816af135c35453ed99c53f23ced547666e9ec15c67e2696c2972338d855b34
Size
40.87 MB
Last pushed
3 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/trivy-operator:02. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/trivy-operator:0 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/trivy-operator@sha256:e232c27011a1bf8780fd152165f86177ca00f4856f8af200ea5c4d6511dc7a1f |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/trivy-operator@sha256:852d4c8ff8a620fbb2fad78904f2d0cde927953da37b7042c8d45286323cc97e |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/trivy-operator@sha256:87c330b4a0cb592a07fa5f2eaf547a5d571a5ba03816695ad9b0c6707df6cbf5 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/trivy-operator@sha256:a6a7a3fbc356159b607293dc49068c065bed05f16cdbe1850855e37e8be70575 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/trivy-operator@sha256:4b9e04bf117313438fa67cdeab210b22d3bf13c82780a631e96ec508ed6c12c6 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/trivy-operator@sha256:082e220fd9106b397120d7c68ec1953aee1aae278d2587945903bedc7f5fd5b3 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/trivy-operator@sha256:adb20587b56f534de084825798b52b1083f6449a5c9ee0617757ff785977b3bd |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/trivy-operator@sha256:f79c2eb0083944c8da78a4f736da9aaf81152c504edd806a48760717e528711a |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/trivy-operator@sha256:6b398f75ae8bb2ff24cae01c99aa9da97b6ea29e08c8d160f4c4e289497b4c8a |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/trivy-operator@sha256:c5f7fe86745c76862b1dc0de431eb67bc795e6bd74869da1f2c06d2ff267b48b |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/trivy-operator@sha256:07019e01801d7186b28f3f23f3de227affe620442dc7e9191e8a3072f3650f6a |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/trivy-operator@sha256:1ace3f0d1aa50e3fa004532f4b8326d470d6a5d6b9fd11425f319c16f03665f8 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/trivy-operator@sha256:d04e36dde28efbc747f0f887958c43974f697e145e2019440f866ec79c127fb5 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/trivy-operator@sha256:d4d37c2c8ad311f1991a5f537a68f016702a1ed9da329d6ef6ab6f3402b9d10c |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/trivy-operator@sha256:9bb054f142433880e7a015adb6483dfcde30377ce2320a7e29a6e6ba46bc984e |