Sign inSign up
Trivy Operator

dhi.io/trivy-operator

Trivy Operator 0.x

CIS
linux/amd64
debian 13
Tags:

0, 0-debian, 0-debian13, 0.31, 0.31-debian, 0.31-debian13, 0.31.1, 0.31.1-debian, 0.31.1-debian13

Index digest:

sha256:9c5497a2c647284146c631bef6829292cc8189d87b5da5d5e7e3871a4c000556

Manifest digest:

sha256:523dd9578fe4dc9d3b1befb02ef6744b7ee7f4d31667a9f4597b0b39e2ccf6cf

Size

40.70 MB

Last pushed

5 days ago

Vulnerabilities

0
1
1
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trivy-operator:0

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trivy-operator:0 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trivy-operator@sha256:75298894829d5947824063b385d7d8e4a6b76db49c779746acceb369401656f8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trivy-operator@sha256:093b27872bb052b5eaddb31cc72759bf16a5fd35f36e52d4c0e4977c5a08e23d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trivy-operator@sha256:9d57ca8376795343e28e98320f2edcb374b096f9dbb52560c466cc7234538847
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trivy-operator@sha256:a7241ebc393c9ad3e192ff51e610426d972590d31401c5ea844e30ea6b0b2a5e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trivy-operator@sha256:de8930384da6e777ec102dd6e96d77f337cf1573e80f1406d39ff2df5742002f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trivy-operator@sha256:483a70136d6c6a601990b82a8483f55ea39979ed181ff5a63cb030ae40bb5183
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trivy-operator@sha256:653f86f7486ab7ca88d602713f8d534b385c38bc8f346a95ae9384edecffdef2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trivy-operator@sha256:e5cc135bd4c45a69614b1f8ebae414b0a4b471d0846b79dcde63477bc92f5320
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trivy-operator@sha256:3dad879ac1dfbbea0bee473d1de513002ce7c19c15b6ca3b72ab4627e8a7b7b8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trivy-operator@sha256:08c6e61ace09077b6edfabbbdffef7c0833aac74b88d911511aa23f9a084e57b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trivy-operator@sha256:661a5b62f160b04c5e8e1d81894ff858098365d1edd966c5ba7b57be79882e68
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trivy-operator@sha256:7ef6cba1c6df5300871ec2b88476aba738faf12dd10953df2ae11308b0e7aae0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trivy-operator@sha256:fe8cd1b03b3c7f971baa5781ed221657d1729a26a92e63cc62e9c9c8746bdc73
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trivy-operator@sha256:610ebb81e960c330e84130fe31080136ee0cf3df89f21b0fff7f1c4e35f33ef3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trivy-operator@sha256:caab358d96668c0f1420c74009532b769c48389461bc50595459a878ea98de6b