Sign inSign up
clamav

dhi.io/clamav

ClamAV 1.4.x (base)

CIS
linux/amd64
debian 13
Tags:

1.4-base, 1.4-debian-base, 1.4-debian13-base, 1.4.6-base, 1.4.6-debian-base, 1.4.6-debian13-base

Index digest:

sha256:828bc0dd4e132fc73125cb6734171d9a6baed2dd0ed594f631335a0e1f1bbe9a

Manifest digest:

sha256:3e8de548bc471676f8f3e59a04019381bfa0a90f5a7c650353dd24005640275f

Size

36.06 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
1
1
0

Support

Active until Aug 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clamav:1.4-base

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clamav:1.4-base --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clamav@sha256:2f94791843de82dee50587f9406a9058f3f928141544fdfca5a93753f8a5b5b8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clamav@sha256:de79f25d2ecf7b1e6494827695d18f6ab155482d37f769336f7acc9eb9652845
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clamav@sha256:5c872ab7a826e38bda6a19b16d7ff74e5f5545672f91cf798c50052c1b9b9d9b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clamav@sha256:56c717f90a46c683259f21cfc5ecdc33079808ba216fd5aedb15e5325c9e5b46
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clamav@sha256:43b8d8ad1e80dea299f637c03e9f39bc8f3c76ed7c169bf120bb5c226d73bc32
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clamav@sha256:2bf01cdfdd042adb4aaa70c635925e214f2f871888de67dc6834355c6e38eb8e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clamav@sha256:9ef14559286638cf1fcdabfc83f2633ff0c6585046c57a6ee7083221dec362b8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clamav@sha256:0ef01fff883ff087474e9a6b9082f234de499c6283c596f87277e5d5d2e8d3bb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clamav@sha256:0430e6199dd017beaa1cfbc47199b50a8b6f8ee098a98a1c11abebb537658ecb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clamav@sha256:a5d85ce14f1d3bda9b6603b7d44d158178f96e7d92066be863c5d8cef982f7b3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clamav@sha256:5b1b8e2afe3033dc0a590c219a90c0b4e9d61e1ad8cad13373a883254de36130
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clamav@sha256:3f47d1b14a74312022caab63d874404f29a1e45f1f6a84c785f9ee59e8e86ac2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clamav@sha256:bf6ba85c1d546653c3bb7fe40ec85ff60f8fd1a796f11f2d459d9d93971cd122
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clamav@sha256:d57c311d26f1a23cfd54ba53ffe4bc3c62b202ddcd1bf3aa3e71a526af4ded5c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clamav@sha256:732acaa0e00b69f0dc0e34f1db7bfc2d0a78732f6f9a9d911c2d99a47e55ee74