Sign inSign up
Trigger.dev

dhi.io/trigger-dev

trigger.dev 4.x

CIS
linux/amd64
debian 13
Tags:

4, 4-debian, 4-debian13, 4.5, 4.5-debian, 4.5-debian13, 4.5.16, 4.5.16-debian, 4.5.16-debian13

Index digest:

sha256:ee979beaf05d71265b4d29d5f11bdfc794da96f9c8c5b2b4bd13b8b211c88f2d

Manifest digest:

sha256:6af9da381ce0a81e5d0ff2e834759d1a32faaeb5703fc84c6e89a676c1237ec1

Size

244.81 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
5
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trigger-dev:4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trigger-dev:4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trigger-dev@sha256:0c69a3dc0e6d85e10d6be247b6721fb773f640b9c1db21951881826dcbf738e1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trigger-dev@sha256:6de45400dd1fb2bdeca41f102729a1c8eaed095e9569a4d05afb38485bf9079e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trigger-dev@sha256:14d67acb7ce395b82fad05a9f75960e53a5cce82b6f2fdb5bf76dd0969ddf69d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trigger-dev@sha256:851569be3e32ac5f2e008d61d3e834d216d387eea818318049547fe497cd2eb7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trigger-dev@sha256:4f86cc3518defedd45c2ecb1efe1119ccded1bea5a8fc5e189e5532b3095d7e1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trigger-dev@sha256:a8db937729d11a2777adfb90aa0de9d61b1aa0b6d78252b330b6ef719cb390e4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trigger-dev@sha256:4332b55209e0e8a3095b8e4765a6d6d8f4799e0635b547aae2d119d90cb8ab43
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trigger-dev@sha256:6a1d07e737369a4ae3e8c7ad10e151023791877efe6ced2158b4c1bd07d881dd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trigger-dev@sha256:4e131afd5190ab5250b1d3d0693e86335bd818a5246dd7fd2ff96ad12ff1b041
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trigger-dev@sha256:7cf728e7bd2ad615ce52c23e30f2b3458eb7e8a01681fa9f44c3de7788dbfab4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trigger-dev@sha256:c6a97192e5cbfee91a1b77ecb22b31cacaf5dc730d40ca3bf19bdd94e3cb850b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trigger-dev@sha256:344636907b9a45873234b46c9e4d99a95679088738dd71a57fcb9d34820e1f5e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trigger-dev@sha256:6f7b8ce0d7ef578a6dac3693f68f2cc07000a6deb8e266dcc93bdf02e30dcff6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trigger-dev@sha256:5650da36d01962be7aa8f8e4bac8a2a1c88e02273cb9a40a73670d1c4f56c51e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trigger-dev@sha256:da00240753aa4f7dc15ff82250e89c3eceb0f3a84984774b7485687634bd2b2e