Sign inSign up
Trivy

dhi.io/trivy

Trivy 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips-dev, 0-debian13-fips-dev, 0-fips-dev, 0.74-debian-fips-dev, 0.74-debian13-fips-dev, 0.74-fips-dev, 0.74.0-debian-fips-dev, 0.74.0-debian13-fips-dev, 0.74.0-fips-dev

Index digest:

sha256:7fe37e59ef54c208d2b247431a7f0137c678de6cddf955740f05df9f02f6fde8

Manifest digest:

sha256:0e7861926dabedac4ba043a838ee55cae44bd89d692abbc2f4adc61073d72b1d

Size

106.88 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trivy:0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trivy:0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trivy@sha256:5f4bb49478825b13fccd2538ecd708df99bdc88df67ff4b10e0793961078965c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trivy@sha256:f5d5e275be494aa987cfefcd4c8b5fd62af2951b4524c921f7f74c2301d8457d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/trivy@sha256:77ca4400f35c4109bb590c615047a82127f30f8edc85a97996ebd859655f7b8b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trivy@sha256:d23e6ced839b27448431e376c702aba4f722c4af0a1556762e621fa9144db72e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/trivy@sha256:42a111c8260a9bc790fda02d67204e7400f0740d0909b6d715244e260730c3da
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trivy@sha256:07c2a5d24844dbd6ca13a143eed636525ae1655606777dd18da1c9a4985b6375
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trivy@sha256:8d35527df275991adde8554e0784b9afebcb0b2ac0c7c14032b9e9e27975bf37
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trivy@sha256:eee3a5b5db10da50c4947ee505de6a8f0029280602db2c4c55aa3a3232033b15
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trivy@sha256:81825fe6fa46b4d93423687d2630ab1dbd0f3076c42527ed0babf775ec7e34a0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trivy@sha256:aa0de0b04a3897f4240520a9c24c69f6646273668fb1f7984ec6ba526e210e7b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trivy@sha256:5822feabe1be1c7829411207d78fdf02b2db71f4e9305b529489134669050eb7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trivy@sha256:0da5777d9674ee012168c2c3066035ec562e42952d2ab283e8f60e67b272d41e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trivy@sha256:9a4aa8130e01005189339369fec86a1291973065b8bc2d6f9c9df0e6dfb19249
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trivy@sha256:5eaecdf178161da9d729a6439c6d9648fdfc065e88cdefcc4e2e9889f5174f3c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trivy@sha256:2faebf94c2d37a85fac42082a7d01b2bc311fc930f1ebc547b19b0a712c38020
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trivy@sha256:e9c9f66e7f0799ec402b3aba491e3ef732991ac66742539eada9e060298f9986
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trivy@sha256:4985969d7238e5dc1497fb5058edbc65fd1db81b878a70b230f84c62dc82261e