Sign inSign up
Trigger.dev

dhi.io/trigger-dev

trigger.dev 4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.6-debian-fips-dev, 4.6-debian13-fips-dev, 4.6-fips-dev, 4.6.3-debian-fips-dev, 4.6.3-debian13-fips-dev, 4.6.3-fips-dev

Index digest:

sha256:7c95d4aca27549893ab27319f40f9ab19677166536e1c4ec27ff49c5fc05e566

Manifest digest:

sha256:24cd9b8feffff86ad787b2fcd7aab6c19c4ac007b134cea9ba02531d91a624ee

Size

273.61 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
5
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trigger-dev:4-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trigger-dev:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trigger-dev@sha256:4c4506c4fdb9d192c4385987839c803afd32039b767180585604910b5d27c20f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trigger-dev@sha256:55aa589e5a589721b6a320a61a8716dac5eb613ef560c27a408579a3867207e5
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/trigger-dev@sha256:66bc4841e69308c93cae756abacb68871b8bb05c77eeadf1bee232a8e3bf09ea
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trigger-dev@sha256:7f099fa633f30e882363ef806c7941d16955acc9f2badd1d2215bd0c41d5b13e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/trigger-dev@sha256:83fb8bf79601d2d271d4cf82842a56595fd0deb445174ba0f6c584afb7df6b64
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trigger-dev@sha256:85e536ecda96dc6104ccef32949d734419f6b323309dc1b5fa5f8a091d825f49
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trigger-dev@sha256:f177e6833b69bd6d3b9e27a917e96031f5334fda774222804d8b87874f029c18
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trigger-dev@sha256:83cdeeb367481578c251b4e0d3b3a09d9e5b1509bbb65065c455356ca86cbbfb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trigger-dev@sha256:c0fdea19a541315ff2d1e33dc270dde841bb99502ead52faf09abbbc29006c0c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trigger-dev@sha256:a736c761b83144d2f000034f830044310cf7e50d9fe3f408f6f09ae27f711a90
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trigger-dev@sha256:82411b23a9f5ded58da5b02446d76be6279f4af47626434591cc51de31437d87
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trigger-dev@sha256:e40ccbee26ec1b04867b706529162d5cc0f1346e8983c27b74420a5e28394b12
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trigger-dev@sha256:5589716e4fddf3b3b9361994ae7d0114bd3a4622e8c61f29f11ae53924238bc7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trigger-dev@sha256:e97e1a16f463ad41a22c35ce3b61db310ee1d816c7ef0724015c69a8f91bbafb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trigger-dev@sha256:8311a8ee1310a5847a63fdcd2922c2653f3dcf6a598cb508fdb85ce2309ffc55
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trigger-dev@sha256:9854694bb5ee28c8db23127e38b5bdda5322e9dd7364d8bdc8c9b2ef75e6aa28
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trigger-dev@sha256:f162ff79121144d48db8b509f7b188aba69d27782445230aa6eed4b3c55ef59e