dhi.io/trivy-operator
0-debian-fips-dev, 0-debian13-fips-dev, 0-fips-dev, 0.31-debian-fips-dev, 0.31-debian13-fips-dev, 0.31-fips-dev, 0.31.1-debian-fips-dev, 0.31.1-debian13-fips-dev, 0.31.1-fips-dev
sha256:4ad9191f3c08595b11fce2087186473e11d202a4fc8a990354bbb7a967ec5ba1
Manifest digest:sha256:897a076b572be168554a03d5459751d479bba1c220f0a4073938ac5f99bbc8aa
Size
101.39 MB
Last pushed
7 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/trivy-operator:0-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/trivy-operator:0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/trivy-operator@sha256:2fe94f7578a7778d3309c123fea358481cfc89a57824460dd69f11b4cf245368 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/trivy-operator@sha256:1836ac6471b8448d124100a9d835cff9e60545cdd138545133ea4f50821cefa6 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/trivy-operator@sha256:4d8dcedee60e1e30b0475cef5ed68da1527a5888782bc93758ff3913a142d814 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/trivy-operator@sha256:81053a2d32caa9a6194cfecffc76d7622b1a5b9e8275ed01596da099e7bc5982 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/trivy-operator@sha256:4ba4cc5cfd18f038ba3464882336db2e547ec2bc5050fc890cbab825220db11c |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/trivy-operator@sha256:031ab88e4579de629cdb5815564b0741f207871dfc75473b858dbd51c139b9b1 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/trivy-operator@sha256:8f6ff959efdac4eb3d9703c387fbf2c75a957b3fdcd8169408003af897146036 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/trivy-operator@sha256:cc91442ec39d6973c93e0f12588d11f66c44f4d657b8d844cfb4d87492e426db |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/trivy-operator@sha256:ca86b63745915eb57c5dda336467e6b5fc05ce732aa44b3443036ccf98039d89 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/trivy-operator@sha256:23488a90b585e207f8a033d574c5e8f54dcb9bf865afd6d328c76ec2fbfbf3f6 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/trivy-operator@sha256:2089b500873babab5fb826039c3ccc822e08877f7fe6df417fb4566b6726a443 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/trivy-operator@sha256:01db420e7cf9c409ee653b1064c659481df0c6b778eb23830c6b6e8d76262557 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/trivy-operator@sha256:740a3202850845a30256bba0eec96d9bf0cfd13ce2e43c79cbeab68c22aeac9d |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/trivy-operator@sha256:6afc1f957a500b42545db144888b34c8526c8dbde9021c72fad2475b00e64b5a |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/trivy-operator@sha256:3db409716f1b10e8aa08fc85f86516b961b7c18b599fb518b2a8a80910069897 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/trivy-operator@sha256:6c69d68324e6de7d05babb190d0c16763ce99b3f505d60256b2e3d22133c1f50 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/trivy-operator@sha256:2f3e432a80ed8871d1066a31452b7c0000c9b19ead587234b726ef30eff9fb54 |