Sign inSign up

timothyswan/trivy

By timothyswan

Updated 4 months ago

Trivy vulnerability scanner rebuilt on Red Hat Hardened Images (RHHI)

Image
0

798

timothyswan/trivy repository overview

trivy — RHHI rebase

Trivy is a comprehensive vulnerability and misconfiguration scanner for container images, filesystems, git repositories, and Kubernetes clusters. This image is rebuilt from source on Red Hat Hardened Images.

Build
  • Base: hi/go:latest-builder (build) → hi/core-runtime (runtime)
  • Source pin: full upstream commit SHA recorded in build.yml
  • Version embedding: -X github.com/aquasecurity/trivy/pkg/version/app.ver
  • CGO disabled, -trimpath, local toolchain only
  • Note: GOEXPERIMENT=jsonv2 required — trivy v0.70.0+ uses encoding/json/v2, gated behind this flag in the RHHI Go builder
Supply-chain attestations

Every image tag carries:

  • cosign signature (key-only, no Rekor transparency log)
  • CycloneDX SBOM attached as OCI attestation
  • SLSA v0.2 provenance attached as OCI attestation
  • OpenSSF Scorecard: 6.4 / 10
Verify
cosign verify-attestation --key <cosign.pub> --type cyclonedx <image>@<digest>
cosign verify-attestation --key <cosign.pub> --type slsaprovenance <image>@<digest>
Tags

Tags follow the pattern <upstream-version>-rhhi (e.g. v0.70.0-rhhi). Always pin by digest in production, not by tag.

Tag summary

Content type

Image

Digest

sha256:b25f71fd8

Size

62.2 MB

Last updated

4 months ago

docker pull timothyswan/trivy:v0.70.0-rhhi