Sign inSign up
Trigger.dev

dhi.io/trigger-dev

trigger.dev 4.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips, 4-debian13-fips, 4-fips, 4.6-debian-fips, 4.6-debian13-fips, 4.6-fips, 4.6.3-debian-fips, 4.6.3-debian13-fips, 4.6.3-fips

Index digest:

sha256:69db7d8fe48e8c4077b56921c2b7a79c6fe6130687eccf7d1981da545127d9c3

Manifest digest:

sha256:b5263d01111ab84ca05033ea09d100c9807a50e76abe0a61ffd49c0aec15b7c2

Size

245.90 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
5
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trigger-dev:4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trigger-dev:4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trigger-dev@sha256:5bd852ea64dd1434f2128005dea4a8c31bd0a29fa8e6a1c729a5ba9c2b5a5fe7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trigger-dev@sha256:de29e4d6beab503cee879ba2145a5a673bf30d8c08d3e896204684c0676ae4a7
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/trigger-dev@sha256:09b254e310d40960389f82d5aee4c327445f9157d7805640b3c103918478d6c5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trigger-dev@sha256:b039e976f4e2c6d6c3f9ca8d9d94dcf0119578c5f081b7b7db82929ed50e02f3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/trigger-dev@sha256:409595bd7e7ad676c554da5950beed7115ca7ce33314f68d35c735ecfaebba08
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trigger-dev@sha256:a14e71aab567bce1c1455f26c4d703ada90b8c442052144c0370d775d08713ec
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trigger-dev@sha256:b89a5cdad13b3bfee92dd9aa4cd05059c354258018b2a0ec2b7269cb8a25bb21
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trigger-dev@sha256:beaf940ac230b69b27616a0d546acc2d2a6b63db563179dd52b4360110d4a191
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trigger-dev@sha256:0530652f38eaf5cb5cc0b64d2f969c1792961ca05c32bc182d62cd9e47240288
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trigger-dev@sha256:5fb1094add00ae2bd077d64b0e1269eb5396a0fb4e00700b416af992cad03d3b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trigger-dev@sha256:572d25fbf397f130c1b3ce03e54e738ccddcc3e085df5438a7e6a100dc53eb0e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trigger-dev@sha256:56e07ffcd1f07a4f9ed0d43c53babc8b6208868e8707b0d40a039ff8cc0dff58
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trigger-dev@sha256:f0ecab3d43a585f6b9950ba381e7a7f096056546403cf5ec974476bf3a268133
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trigger-dev@sha256:4b62fddab7dc4a7b5ff915ea84ccd562a4191480827f6d7b01cd440cd106f85d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trigger-dev@sha256:ee08b3967ebdb571e4c2a815268f0ab19dcc1e08f8089928fbbeb910292f177d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trigger-dev@sha256:de1bee1a2e469c610f80dbb15366bfddbb320c4b8808faee27b61d2ed53b2a08