Sign inSign up
Trivy

dhi.io/trivy

Trivy 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

0-alpine-fips-dev, 0-alpine3.24-fips-dev, 0.74-alpine-fips-dev, 0.74-alpine3.24-fips-dev, 0.74.0-alpine-fips-dev, 0.74.0-alpine3.24-fips-dev

Index digest:

sha256:93be36f4f1b7633b04d74acca26875a7c1fcbc9b6da611dfe059ec092c869732

Manifest digest:

sha256:e08357b4e8f0e7afa5da3d49127c369ca44439610e490d53e92ac1883b77a6db

Size

87.56 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trivy:0-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trivy:0-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trivy@sha256:92964e13600068c63eff4e3c3fbaab26632e24e8d3320782b52cce43b0d35180
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trivy@sha256:1a3c5f181b872cc59ef8df501028ab8e4483023cf71f3ba8696cbce55efbc1b7
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/trivy@sha256:7c1a22f5c4317f5193a1a359fa17a14b7ebfd183432d13caec12a14668785e61
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trivy@sha256:95cacc49164fbd170c0aa69c78786a3dfb04c72147f2b25ab53fe2a587fd5095
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/trivy@sha256:aeac6b395f2b4864cfea29f2989683f0787db8e19dcddd5f22c93c1a1b9d8635
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trivy@sha256:b0f2c90c85a15e429b5a82d0d830406f92ba3d3992b20e755fd51908709e7b1a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trivy@sha256:2c44738f76141ba7a507497229bfaf1ed590097f70c12df519639970e75d058c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trivy@sha256:e5f84a08aacc362f61e644746b52518cf5fdd4253254a76797047c710e3594dd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trivy@sha256:799ec9d29165f78f53cce3b9213fd7ad2be7543cf12fd0f7e530399a2e8ceef6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trivy@sha256:3cb6954dedb4f74ce851c48337c86e062163732323f11ca8bfeb4cae8cc5f79f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trivy@sha256:8a96736f2b843aa820db8bfb6a92b582af4975161e9b4012eaf9451c9ae0b552
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trivy@sha256:9e3a54cc8b7346b1183eead99d84a88e2a01e89f40095fc317d630322a53b0e7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trivy@sha256:d5f13b78b0c5f0822be8a5d55fa2ba3bdb38eff60cce992cbbf5ecc90d380896
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trivy@sha256:88632fd141aee0b9709f0e342bf29d2c751e93b5ad067dbc4c4b60256b417ff8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trivy@sha256:509acb610081ab720bc13f5d403f91689aa1a04e8a91de30a3c7af7b99f8b6b3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trivy@sha256:b2c0a1c07be76e41601ea8463e7f7c37cbd57d8c8c5da8c794ccfc21feb7a73f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trivy@sha256:697371706888a45ca1ad69a9476dfa2546a8f5e2891afe10ca5041806e11aeea