Sign inSign up
Trivy

dhi.io/trivy

Trivy 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

0-alpine3.23-fips-dev, 0.74-alpine3.23-fips-dev, 0.74.0-alpine3.23-fips-dev

Index digest:

sha256:2c1947dafdcb6702090d53170a5b992c4cc99225b15f47076841fe62a721e39c

Manifest digest:

sha256:c887c9b8c48d3c4b47f14e5347dcdc5e0242d703b3d57131e908a5ac6833345f

Size

87.85 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trivy:0-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trivy:0-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trivy@sha256:fa092ee414ef56cfd6686a34f9f95f6f952d3dde6f8d1c8ac79adc37544fe9fb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trivy@sha256:48f6390eeb5f9aa2c2ba9205da38e7d8be4e2c9b19de78c96fd72bf0103bb766
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/trivy@sha256:45cea1f9ad99995f4dbc710b6c9f51c390c0cf8297b10339fec374487d93a878
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trivy@sha256:316faba3eccaa44b63e16be6618296fb255f7062e311bccfbdc38e45abde7eb5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/trivy@sha256:d3ee752d1a8e24cbf89ba9c2dd34f35242127d98d25d812e33990292e7a32eb9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trivy@sha256:652004c52c6b32ebb8ce9ffb6afab0c738e82f6f4784c132be2e61dfbb76fab8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trivy@sha256:77275a738477ff590f77e8e10ab169282e4451dd4724bae9b689427a91fa7a4e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trivy@sha256:fa35ce5d4002efbd916020f28ab2cdbd5665b561c82851f472f1981c6ac2ce1c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trivy@sha256:d5cdfc7278877ce956e2460f9f6a14676083f5fd25638562c6fa756bc54daeda
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trivy@sha256:a3f52b08a196a4bada0758515b592523926cef024778048ef5489a6278acf166
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trivy@sha256:298f512a136badbef82e084dd82517983d93330bb960ec1865a73a96ec03d721
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trivy@sha256:957234fed911985e8d28249ef5aba93f6c3671dbc58d5c2b0ec2b9a47ac44e04
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trivy@sha256:e66d4d1c4729893aba7b63483baf6546450cfc836a27dd1c9ffface3bdb00ce1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trivy@sha256:b16baa65b37cb422cec672fa05b667d0ca6a36d5a2e16782da8c9c668c1d27ec
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trivy@sha256:159ed711f6a1560c4be1f8227e8b2ff2c37f8c1caa8900c9f8d75cdd865b1654
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trivy@sha256:90d22c8ab7b202fc5ec1a9923aa7116652a95c1e82b9ea67c960fce6915100ba
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trivy@sha256:eecdfa77ca274453a60b85a78945014705269d9614ec563281060612274d9d62