Sign inSign up
Trivy

dhi.io/trivy

Trivy 0.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

0-alpine3.23-fips, 0.74-alpine3.23-fips, 0.74.0-alpine3.23-fips

Index digest:

sha256:0dbd611ed2ba076e631630ed15d996fcc62a9a37b20b135b4a63fcb095847221

Manifest digest:

sha256:87962db21c8626f56fab78e07745a55ebc511c5b3534f50460d109897a1182a7

Size

46.45 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trivy:0-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trivy:0-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trivy@sha256:eb33b39a6abe9084352f5d30886f36ccf95920181c8b35379b2e0b3295578f1d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trivy@sha256:0474dc8e9d6a018cf99d0335ec0e99db8fc57305d84721925a82ced336f449db
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/trivy@sha256:6caa0a133f1c1545ab576cddd776b62729617280ade0153ecac49759a1e2d63f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trivy@sha256:6c17c30374a77290b90bb3ef413df361e77a14082aacb24301ac14bf3be5be40
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/trivy@sha256:8a1dbc1471769d19bccbdb5f4518ee6d817589b60f73a30bae1ea6699363a518
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trivy@sha256:6b273aa265ebe6cb45fa940a20bad766f7e31c87285545f5dd720c6e0fd40348
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trivy@sha256:8ab81e5050c75e161844d76734bd2c28fec1b52a27d4fa2ea85e731e85ac2195
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trivy@sha256:bab04d7cd29b4af9735f0f498f8b9fdce43aa1614964b40b1009426231cbaa75
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trivy@sha256:76705ed134d7b39c0eba0a20e36c0908367bab3582120d5b17866c607b9258d0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trivy@sha256:e8b7fac345fdfa56390497be21fca825adea8512da3dc465e0d5984283e1e980
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trivy@sha256:85b5c7a42d90d7bdae9da4001b605dd00017d3ab9b7e908c0f8da282201af483
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trivy@sha256:79184d24cd260e9b36e40dd9f26cace4099120eb6fd7381ea76675ca18e5fb04
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trivy@sha256:49ecc6fc27468cb5b6c3b55b5222772932fa354d42519d8ac022c74ba70c89a7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trivy@sha256:dc5bc3f14cd4527ca45bd1ed9d66344d44b195e2d13456789612fcf2af806cfc
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trivy@sha256:e130a82dd01044fc46bfb56a87fcd0dd74b70a4ecad0deac53aa10810bd4d31d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trivy@sha256:e7fbc80034188ca28e83ae8f1f8b1550c644259eac1f4daef2ea229af53b37b5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trivy@sha256:26dec6afee19e8fd1d4818cc713e4371cd08c823de3f1573080e8bb79bd6ae86