Sign inSign up
Trigger.dev

dhi.io/trigger-dev

trigger.dev 4.x (dev)

CIS
linux/amd64
debian 13
Tags:

4-debian-dev, 4-debian13-dev, 4-dev, 4.5-debian-dev, 4.5-debian13-dev, 4.5-dev, 4.5.16-debian-dev, 4.5.16-debian13-dev, 4.5.16-dev

Index digest:

sha256:96ee2de8700e54142f9da129d8cfe9c476d1a3a888eb2e27d01192e7b4895c65

Manifest digest:

sha256:8e118509051b29865816bbe8b06108d6d8185b6bc633cf580bf086484c4eb1c8

Size

272.57 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
5
2
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trigger-dev:4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trigger-dev:4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trigger-dev@sha256:6d62920c378cbce729735cee1923414ea1ae329c0a50135cb1db8d9da31011cb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trigger-dev@sha256:82775f6e7934e07e98c3a046455bd3dff94e40b9db60f0198283ae09bf36154e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trigger-dev@sha256:83e5cf2c8b9471b72987adf822129d105f06c2c9cb473847144d556160d1328e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trigger-dev@sha256:cab11fe06e7b08df11b3fea9228ffb19b894e2b4f8e8f8340e84c1e2cafed6fa
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trigger-dev@sha256:c77bad68de9cfaf33828e3039302dc176a7eda5158af2bed8e07c18aa577b26f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trigger-dev@sha256:d39024d8b40fb1bdfa6cdd35167bcfbf6e17345d6f82e75afb8bb487671b30e9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trigger-dev@sha256:25a97d11ec868a21abd49000ce241efc9dc012fc9060fbd53e3e8b01714063cb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trigger-dev@sha256:a955004571be941dd6a4c06e6e397b023e89d84a3378f2466416d214b46a86a9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trigger-dev@sha256:ec5ef6212369f8f6b7cb9cdcfa422fbb4625ca37a98be30f41390ad0ab8a3faf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trigger-dev@sha256:f4332a414d92a045d38e74e55b5615237f8f87991eca9db73f75d52bf0ea9ffa
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trigger-dev@sha256:6b4054e01b809c193047f1259f5e040cf85dccee7c8b8e0b8406c6e96d8d9118
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trigger-dev@sha256:d8918895ac03d0cfa9db87fce5242b1b51f77320b63696e75d65423d0f908d8b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trigger-dev@sha256:da9508cefe927eaa340d772f703310b482ec105f70573ad95f103d2a9663d1b0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trigger-dev@sha256:cf759d549cff7b457f2df97b632f912dc4e0aa7e997eeb44f769ed779bbfdce3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trigger-dev@sha256:7eb0e20f2c1b6d96758dacb0edc6479082d1adc0fa925355757ec760896315e6