Sign inSign up
Trivy Operator

dhi.io/trivy-operator

Trivy Operator 0.x

CIS
linux/amd64
debian 13
Tags:

0, 0-debian, 0-debian13, 0.31, 0.31-debian, 0.31-debian13, 0.31.1, 0.31.1-debian, 0.31.1-debian13

Index digest:

sha256:ab776a6301cc0abff57d715c7457050510a6d09e2c86a359182a8ef82f5075e0

Manifest digest:

sha256:06816af135c35453ed99c53f23ced547666e9ec15c67e2696c2972338d855b34

Size

40.87 MB

Last pushed

3 days ago

Vulnerabilities

0
0
2
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trivy-operator:0

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trivy-operator:0 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trivy-operator@sha256:e232c27011a1bf8780fd152165f86177ca00f4856f8af200ea5c4d6511dc7a1f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trivy-operator@sha256:852d4c8ff8a620fbb2fad78904f2d0cde927953da37b7042c8d45286323cc97e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trivy-operator@sha256:87c330b4a0cb592a07fa5f2eaf547a5d571a5ba03816695ad9b0c6707df6cbf5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trivy-operator@sha256:a6a7a3fbc356159b607293dc49068c065bed05f16cdbe1850855e37e8be70575
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trivy-operator@sha256:4b9e04bf117313438fa67cdeab210b22d3bf13c82780a631e96ec508ed6c12c6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trivy-operator@sha256:082e220fd9106b397120d7c68ec1953aee1aae278d2587945903bedc7f5fd5b3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trivy-operator@sha256:adb20587b56f534de084825798b52b1083f6449a5c9ee0617757ff785977b3bd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trivy-operator@sha256:f79c2eb0083944c8da78a4f736da9aaf81152c504edd806a48760717e528711a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trivy-operator@sha256:6b398f75ae8bb2ff24cae01c99aa9da97b6ea29e08c8d160f4c4e289497b4c8a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trivy-operator@sha256:c5f7fe86745c76862b1dc0de431eb67bc795e6bd74869da1f2c06d2ff267b48b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trivy-operator@sha256:07019e01801d7186b28f3f23f3de227affe620442dc7e9191e8a3072f3650f6a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trivy-operator@sha256:1ace3f0d1aa50e3fa004532f4b8326d470d6a5d6b9fd11425f319c16f03665f8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trivy-operator@sha256:d04e36dde28efbc747f0f887958c43974f697e145e2019440f866ec79c127fb5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trivy-operator@sha256:d4d37c2c8ad311f1991a5f537a68f016702a1ed9da329d6ef6ab6f3402b9d10c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trivy-operator@sha256:9bb054f142433880e7a015adb6483dfcde30377ce2320a7e29a6e6ba46bc984e