dhi.io/trivy
0-alpine-fips-dev, 0-alpine3.24-fips-dev, 0.74-alpine-fips-dev, 0.74-alpine3.24-fips-dev, 0.74.0-alpine-fips-dev, 0.74.0-alpine3.24-fips-dev
sha256:93be36f4f1b7633b04d74acca26875a7c1fcbc9b6da611dfe059ec092c869732
Manifest digest:sha256:e08357b4e8f0e7afa5da3d49127c369ca44439610e490d53e92ac1883b77a6db
Size
87.56 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/trivy:0-alpine-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/trivy:0-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/trivy@sha256:92964e13600068c63eff4e3c3fbaab26632e24e8d3320782b52cce43b0d35180 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/trivy@sha256:1a3c5f181b872cc59ef8df501028ab8e4483023cf71f3ba8696cbce55efbc1b7 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/trivy@sha256:7c1a22f5c4317f5193a1a359fa17a14b7ebfd183432d13caec12a14668785e61 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/trivy@sha256:95cacc49164fbd170c0aa69c78786a3dfb04c72147f2b25ab53fe2a587fd5095 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/trivy@sha256:aeac6b395f2b4864cfea29f2989683f0787db8e19dcddd5f22c93c1a1b9d8635 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/trivy@sha256:b0f2c90c85a15e429b5a82d0d830406f92ba3d3992b20e755fd51908709e7b1a |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/trivy@sha256:2c44738f76141ba7a507497229bfaf1ed590097f70c12df519639970e75d058c |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/trivy@sha256:e5f84a08aacc362f61e644746b52518cf5fdd4253254a76797047c710e3594dd |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/trivy@sha256:799ec9d29165f78f53cce3b9213fd7ad2be7543cf12fd0f7e530399a2e8ceef6 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/trivy@sha256:3cb6954dedb4f74ce851c48337c86e062163732323f11ca8bfeb4cae8cc5f79f |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/trivy@sha256:8a96736f2b843aa820db8bfb6a92b582af4975161e9b4012eaf9451c9ae0b552 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/trivy@sha256:9e3a54cc8b7346b1183eead99d84a88e2a01e89f40095fc317d630322a53b0e7 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/trivy@sha256:d5f13b78b0c5f0822be8a5d55fa2ba3bdb38eff60cce992cbbf5ecc90d380896 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/trivy@sha256:88632fd141aee0b9709f0e342bf29d2c751e93b5ad067dbc4c4b60256b417ff8 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/trivy@sha256:509acb610081ab720bc13f5d403f91689aa1a04e8a91de30a3c7af7b99f8b6b3 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/trivy@sha256:b2c0a1c07be76e41601ea8463e7f7c37cbd57d8c8c5da8c794ccfc21feb7a73f |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/trivy@sha256:697371706888a45ca1ad69a9476dfa2546a8f5e2891afe10ca5041806e11aeea |