Sign inSign up
Trivy Operator

dhi.io/trivy-operator

Trivy Operator 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips-dev, 0-debian13-fips-dev, 0-fips-dev, 0.31-debian-fips-dev, 0.31-debian13-fips-dev, 0.31-fips-dev, 0.31.1-debian-fips-dev, 0.31.1-debian13-fips-dev, 0.31.1-fips-dev

Index digest:

sha256:4ad9191f3c08595b11fce2087186473e11d202a4fc8a990354bbb7a967ec5ba1

Manifest digest:

sha256:897a076b572be168554a03d5459751d479bba1c220f0a4073938ac5f99bbc8aa

Size

101.39 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trivy-operator:0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trivy-operator:0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trivy-operator@sha256:2fe94f7578a7778d3309c123fea358481cfc89a57824460dd69f11b4cf245368
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trivy-operator@sha256:1836ac6471b8448d124100a9d835cff9e60545cdd138545133ea4f50821cefa6
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/trivy-operator@sha256:4d8dcedee60e1e30b0475cef5ed68da1527a5888782bc93758ff3913a142d814
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trivy-operator@sha256:81053a2d32caa9a6194cfecffc76d7622b1a5b9e8275ed01596da099e7bc5982
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/trivy-operator@sha256:4ba4cc5cfd18f038ba3464882336db2e547ec2bc5050fc890cbab825220db11c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trivy-operator@sha256:031ab88e4579de629cdb5815564b0741f207871dfc75473b858dbd51c139b9b1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trivy-operator@sha256:8f6ff959efdac4eb3d9703c387fbf2c75a957b3fdcd8169408003af897146036
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trivy-operator@sha256:cc91442ec39d6973c93e0f12588d11f66c44f4d657b8d844cfb4d87492e426db
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trivy-operator@sha256:ca86b63745915eb57c5dda336467e6b5fc05ce732aa44b3443036ccf98039d89
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trivy-operator@sha256:23488a90b585e207f8a033d574c5e8f54dcb9bf865afd6d328c76ec2fbfbf3f6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trivy-operator@sha256:2089b500873babab5fb826039c3ccc822e08877f7fe6df417fb4566b6726a443
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trivy-operator@sha256:01db420e7cf9c409ee653b1064c659481df0c6b778eb23830c6b6e8d76262557
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trivy-operator@sha256:740a3202850845a30256bba0eec96d9bf0cfd13ce2e43c79cbeab68c22aeac9d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trivy-operator@sha256:6afc1f957a500b42545db144888b34c8526c8dbde9021c72fad2475b00e64b5a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trivy-operator@sha256:3db409716f1b10e8aa08fc85f86516b961b7c18b599fb518b2a8a80910069897
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trivy-operator@sha256:6c69d68324e6de7d05babb190d0c16763ce99b3f505d60256b2e3d22133c1f50
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trivy-operator@sha256:2f3e432a80ed8871d1066a31452b7c0000c9b19ead587234b726ef30eff9fb54