Sign inSign up
Harbor Trivy Adapter

dhi.io/harbor-trivy-adapter

Harbor Trivy Adapter 2.14.x

CIS
linux/amd64
debian 13
Tags:

2.14, 2.14-debian, 2.14-debian13, 2.14.4, 2.14.4-debian, 2.14.4-debian13

Index digest:

sha256:00eb66fd8715e70034bd1f5cdd8eef1f3b53d0c72b5fe27c37c99ec49409a276

Manifest digest:

sha256:06446c73a17d0be4ed8b35d1b262c2e4e0f5463eb655a947f1263975746fb519

Size

55.20 MB

Last pushed

14 hours ago

Vulnerabilities

0
1
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-trivy-adapter:2.14

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-trivy-adapter:2.14 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-trivy-adapter@sha256:0dd86c4a558c0ff7f3ce33293113fb850f33f0f45db2ac6a6099180390ee9d26
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-trivy-adapter@sha256:76f38daa3e851e4a7ce25bd713a4734af53c51f3f2d9645b85a77a8a8c94b4cb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-trivy-adapter@sha256:818e1833881c5c6cabf64c652f5fb40b3c5a91f72aac4dfba5c4a163ab992542
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-trivy-adapter@sha256:bb03429f10820f9be5bbfaf80aac2b2180577b32c1d317c7189d79fff01bd81a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-trivy-adapter@sha256:03a17f326c7612b465e0aeba2d70fcdc75cd41b0c5eabbc573f7f1e1e101a863
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-trivy-adapter@sha256:808307358a18a2aef7d7b0c9635c414da5b9a01d0d1471ff36094546acc4d698
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-trivy-adapter@sha256:3f1764a47810922cc68e90eb50cf45b88448b58d1c5a94f21f4a3d19a8ca727c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-trivy-adapter@sha256:d6f62a08c4b4f04cc36b7338b989c39572ee8c8ad899836417f405c5a4980fe7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-trivy-adapter@sha256:7cbc0ebc434a980b38e7c50ced2da69f66b113be7a04676cc43ea6a3109be3ac
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-trivy-adapter@sha256:56d2a1993a93c6a96e9a3fb5cc2298b4c323715c2b3c6a25f635ca57a4b479d4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-trivy-adapter@sha256:5d5be85b46e566b502b8746ed5bb7825d9853111778f6ecb1214df5deadf3783
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-trivy-adapter@sha256:a032b40b6e609116eb767dfeb77a2b58fa1bb18b5e26b1066e9a9acc690111f5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-trivy-adapter@sha256:683df4f2ce5ea13c3dd1b6661a2ea60bba1b542af59db799a7d15ce5942a5308
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-trivy-adapter@sha256:2bea3a8a2921423a0c8311999fc88e1cfb5e5dd499e25737d08b5688b9f87dd2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-trivy-adapter@sha256:8b24f2f4e2ee473f2daaa9b9039e187ee2b7b5631fe2e5ff21017bb7611a8f2e