Sign inSign up
Trivy

dhi.io/trivy

Trivy 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips-dev, 0-debian13-fips-dev, 0-fips-dev, 0.74-debian-fips-dev, 0.74-debian13-fips-dev, 0.74-fips-dev, 0.74.0-debian-fips-dev, 0.74.0-debian13-fips-dev, 0.74.0-fips-dev

Index digest:

sha256:63f649764c18c17a4023fd508906d8df5a82f58a2fc47771b0720eb20ee7135d

Manifest digest:

sha256:50aeac45f7de8fe039ee20d510dbde0b08f0c4d0632866c877358ec5ff099c19

Size

107.20 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trivy:0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trivy:0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trivy@sha256:20a79bbea58940762d2a4f43f7543c05cd4e007d2d5db946160527b0a00a9618
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trivy@sha256:58a940c6578d25c5ab9ff6fb59c2c5d789c1fe18d939a8b0c515beb0639ceae0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/trivy@sha256:7133b805e32bac3b85b3e0f0707472584a338cae12c4f914ecda8a812265e762
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trivy@sha256:07c0250ad385dc0781292de39cab133dde39993d3ca13b716d05b63ed8f03a98
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/trivy@sha256:3693f844d9e695ed41491dfa1c816c7b9f7918bb0f6b3b9c46bcaad2955e32d1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trivy@sha256:2db5fd0a003c45b0a6c9143e56c567d5d6f811deb8bd4dd5486a5c338bcf060c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trivy@sha256:4555664c1998912a8015de9e773228fbb854fa2de0840d9114dc0b2524795054
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trivy@sha256:fe0e9f95a6c41dd4b95aa7df4688cb28bc5464704f15388c25b008c294f97af3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trivy@sha256:fb518028022829b6fb1d5f1f7b80ce3a8743d7ca6239b8f4041c206ff4344ecd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trivy@sha256:681599f035f923a7b1b9a2c57b3652f60d39efe9eab3e10bf2bd4c5047b6b8ab
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trivy@sha256:45121e1a126ce8f2d7aac6098021e6bd861fd937db711cc1349f291fca7f0b03
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trivy@sha256:10b78d30460bb3072e341068692fc5355ef12a689bf8937f83e70902b2d5c60a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trivy@sha256:a9198634e530c3d480171dd6a731d0b4c89ce0e00ae64765839fafeb3453d28a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trivy@sha256:f2332c715321cfa9bf37aec9e90af634912a4b9a78248e9a0869fc6e3e443447
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trivy@sha256:a5f5315253535c255a261aad67eddc5bb0ca9714e1c36235dccd846b6fd3e522
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trivy@sha256:ed23d9ab3111798d155c888e836345c01695bb416695744bb9c078b839be76c5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trivy@sha256:6e53d64df6bc3853c41c29f549c3337f98e0491ac3a9731943419cd8c69b50b8