Sign inSign up
Trigger.dev

dhi.io/trigger-dev

trigger.dev 4.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips, 4-debian13-fips, 4-fips, 4.6-debian-fips, 4.6-debian13-fips, 4.6-fips, 4.6.3-debian-fips, 4.6.3-debian13-fips, 4.6.3-fips

Index digest:

sha256:86a57ba03abe1f47e8240b91fbaf3ad242a194fc283d73bb6a51fb8f06bc46d9

Manifest digest:

sha256:74f41d4f1cc0be8507b5c32e4c09f3e3173e7a90519e29c3f401060ba773bd5c

Size

245.90 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
5
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trigger-dev:4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trigger-dev:4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trigger-dev@sha256:6fd5a6a538e72cb02777599cff2bddcb6f2cfa857da946c69d6e5e47e612e55e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trigger-dev@sha256:a0414ff3904d17e71d5900baf7dbce830591c68364d7f52b42f45978a90fade2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/trigger-dev@sha256:a812004555d813a5643830504c8aca61fb46b6b55240d955acdc1f3d4f4c7f62
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trigger-dev@sha256:6bc9ff0761493a80d049062af5c8bb12115f839ae025ff4a7b8b24da4c4afe62
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/trigger-dev@sha256:006ffcbd405c3f572450a9cfce5f79339eb4c438cab4173a2ef954a06f58a2b1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trigger-dev@sha256:79972cd29d66ee24759af0d5dade5f0cc1c988a9017546159219268acc289df6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trigger-dev@sha256:ecd672619a869a9ff013087438665d6c43fe82781c2452fdd03f8e0634ba3d55
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trigger-dev@sha256:c199eb6cfed817b843bd50a481187515e1361644c7d373dab2a626d556e8ea59
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trigger-dev@sha256:e5feeba9828e03aacdc666769e5dc034501c38070f5e3be39dd81898a8f525e8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trigger-dev@sha256:770da4832d079c90b6bfb5098dfbdfdc7cf73ca3d09858490ade07decd04f34c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trigger-dev@sha256:d974ea19483bd170cbb0c8e9e4372ea000107b90c89032992c65a5d6e61862f2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trigger-dev@sha256:0ce0279cd5f5c729642b80f5009e1080dc66fbc5b299abe759bf6a70640b148d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trigger-dev@sha256:9b1a32f82dd41be926aa3cfb5d85c9823be2462033da013563a7e6d15bb766c2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trigger-dev@sha256:7036ecd5021c998a6a45dcb87026a21bfe97f7251978885ec21f381094384fc0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trigger-dev@sha256:c174569b488d808d3d61839f4305aee27d0742363a0228bc507e14689e14bf7c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trigger-dev@sha256:eb706eb381f21b88fad7212cc6b90d5b8d28df1a7a3cf88024f703293f263745
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trigger-dev@sha256:bdde25c2760777ee7eca70e1c3d7ec3501b53b90913da30bea164b0ccd7404c1