dhi.io/trivy-operator
0, 0-debian, 0-debian13, 0.31, 0.31-debian, 0.31-debian13, 0.31.1, 0.31.1-debian, 0.31.1-debian13
sha256:9c5497a2c647284146c631bef6829292cc8189d87b5da5d5e7e3871a4c000556
Manifest digest:sha256:523dd9578fe4dc9d3b1befb02ef6744b7ee7f4d31667a9f4597b0b39e2ccf6cf
Size
40.70 MB
Last pushed
5 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/trivy-operator:02. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/trivy-operator:0 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/trivy-operator@sha256:75298894829d5947824063b385d7d8e4a6b76db49c779746acceb369401656f8 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/trivy-operator@sha256:093b27872bb052b5eaddb31cc72759bf16a5fd35f36e52d4c0e4977c5a08e23d |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/trivy-operator@sha256:9d57ca8376795343e28e98320f2edcb374b096f9dbb52560c466cc7234538847 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/trivy-operator@sha256:a7241ebc393c9ad3e192ff51e610426d972590d31401c5ea844e30ea6b0b2a5e |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/trivy-operator@sha256:de8930384da6e777ec102dd6e96d77f337cf1573e80f1406d39ff2df5742002f |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/trivy-operator@sha256:483a70136d6c6a601990b82a8483f55ea39979ed181ff5a63cb030ae40bb5183 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/trivy-operator@sha256:653f86f7486ab7ca88d602713f8d534b385c38bc8f346a95ae9384edecffdef2 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/trivy-operator@sha256:e5cc135bd4c45a69614b1f8ebae414b0a4b471d0846b79dcde63477bc92f5320 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/trivy-operator@sha256:3dad879ac1dfbbea0bee473d1de513002ce7c19c15b6ca3b72ab4627e8a7b7b8 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/trivy-operator@sha256:08c6e61ace09077b6edfabbbdffef7c0833aac74b88d911511aa23f9a084e57b |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/trivy-operator@sha256:661a5b62f160b04c5e8e1d81894ff858098365d1edd966c5ba7b57be79882e68 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/trivy-operator@sha256:7ef6cba1c6df5300871ec2b88476aba738faf12dd10953df2ae11308b0e7aae0 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/trivy-operator@sha256:fe8cd1b03b3c7f971baa5781ed221657d1729a26a92e63cc62e9c9c8746bdc73 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/trivy-operator@sha256:610ebb81e960c330e84130fe31080136ee0cf3df89f21b0fff7f1c4e35f33ef3 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/trivy-operator@sha256:caab358d96668c0f1420c74009532b769c48389461bc50595459a878ea98de6b |