Trivy vulnerability scanner rebuilt on Red Hat Hardened Images (RHHI)
798
Trivy is a comprehensive vulnerability and misconfiguration scanner for container images, filesystems, git repositories, and Kubernetes clusters. This image is rebuilt from source on Red Hat Hardened Images.
hi/go:latest-builder (build) → hi/core-runtime (runtime)build.yml-X github.com/aquasecurity/trivy/pkg/version/app.ver-trimpath, local toolchain onlyGOEXPERIMENT=jsonv2 required — trivy v0.70.0+ uses encoding/json/v2, gated behind this flag in the RHHI Go builderEvery image tag carries:
cosign verify-attestation --key <cosign.pub> --type cyclonedx <image>@<digest>
cosign verify-attestation --key <cosign.pub> --type slsaprovenance <image>@<digest>
Tags follow the pattern <upstream-version>-rhhi (e.g. v0.70.0-rhhi). Always pin by digest in production, not by tag.
Content type
Image
Digest
sha256:b25f71fd8…
Size
62.2 MB
Last updated
4 months ago
docker pull timothyswan/trivy:v0.70.0-rhhi