Sign inSign up
Trivy

dhi.io/trivy

Trivy 0.x (fips)

CIS
FIPS
STIG
linux/arm64
debian 13
Tags:

0-debian-fips, 0-debian13-fips, 0-fips, 0.74-debian-fips, 0.74-debian13-fips, 0.74-fips, 0.74.0-debian-fips, 0.74.0-debian13-fips, 0.74.0-fips

Index digest:

sha256:1716e72d83ea8708d14cdf999b38623187cc60b4d2600efafc8d61cff48b32fa

Manifest digest:

sha256:5516fe6de98f6e283b4cacef718840d7c5017ff2755123b8864c9cf3088d5e12

Size

47.13 MB

Last pushed

1 day ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trivy:0-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trivy:0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trivy@sha256:4a705e8708a1a2aa34491951c320c4690bd2dfac79b550d15981145eb5364323
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trivy@sha256:418c85fe810f493a307bf5f333a5c381e766f2535d3fcbea0b95ab64b5bfb06f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/trivy@sha256:f38fae6b61fc3ed637277928703c85de1df259d9f161c43c40de62b1785e6c1a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trivy@sha256:7a42c6dcef73d894ce30cacfcabe5b0207b99b8376f9cbee4f3ad6a523895a7e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/trivy@sha256:7d286ef2f84ebbadcf2d9ec257816d74d6edd1ee99f7d58207ce8bae1605d6a3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trivy@sha256:72ae603f1537dd4118bd507ce75c4ef3c483a02b3730f6d408951092b2048af4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trivy@sha256:835eb99c604c890e7ea7dd8d33b998132c2d5de20cbbb5f14acf83592c44ebcd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trivy@sha256:7c59e492029829c89d56ff8036daef22a3a306f2d71fc7104313b854b9baf727
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trivy@sha256:293d46d9ccbde128a4e0797475da4215659992527fe90ec278b0cee265dab9c5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trivy@sha256:c97f413be36d7e60a319fcc387f8b86ad3bf25c7bbb0a4a5efa35163a336c4f1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trivy@sha256:ae0ea94bf3624b44480c2b8d7666d78916da5c67faee7103af2dd3abf90a9b60
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trivy@sha256:b45f2fae3f42e155262d177a1a410b3883fb1d354a6b379a020fbc03501bc7d0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trivy@sha256:0ac9a7f1c4d492d5b5b90cb2c39624f7b1f626019abf7b3c38ba803ea5f402b0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trivy@sha256:02b2bfad7251ceff6e7652683b085676fe18091db2cf5b77f38324fd87168b73
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trivy@sha256:d220c6fc51a0aa69119a6abea8eef64c271fcf8ac280e44a46f1857b99938252
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trivy@sha256:f7ba452276a49ec0bb31d8648e6139250b5ea6262326b0ffc9d3d43388b1f0af
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trivy@sha256:620be761a56ac1da22f0fcc8a888f88416ea129d0876e232573d9225c14b0044