Sign inSign up
Trino

dhi.io/trino

Trino 483

CIS
linux/amd64
debian 13
Tags:

483, 483-debian, 483-debian13

Index digest:

sha256:ba61c6e54f3fac28ec55f2be642edd5ea6b1dd374c20b223348e53743ecc7ee6

Manifest digest:

sha256:0c6e9c8bc6402a096025dd82ae5e26d8a8dc969ef4385eb11e0dd7d66783be23

Size

285.98 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trino:483

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trino:483 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trino@sha256:7bdd43b92861271a7eafdf0814c0f58f6b159b45d36576fe8eaeffcaae8fad29
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trino@sha256:5c2d71ab3ea838f53962fec45719bba3cd3491080e311d56e90aa9c5e35d2e07
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trino@sha256:f3e6009eeb1de3f362fad125316f9ee6b5c697ea7d13dda05b700be11c0fc752
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trino@sha256:e71c1e5b0fa8f0780cae811d3f67082b62aa76587e62a82ca44947b3e1cf7426
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trino@sha256:24c15c784b9aea7a94b74e5ae22547f9505ca72320d63418cc83eb2ffaed48d3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trino@sha256:8412076c10e9e282f228db6d8e7a961a5fe1d951548caa998e261c3fc0c20cdd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trino@sha256:5927fccd0fcce6719f9b95e0e39fb7ec700679600c5977c7439e4ee546d4132c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trino@sha256:61fdcdb3612a94c3e49a105cd8b400c0d0f581dcc5e039e4d7229a9890db4f09
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trino@sha256:4fc90be4f0f6bf79c181914119a2e56cd89ea93acd017654ae26b93b91498667
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trino@sha256:56112eeb46c6f533f3af446f881d7c8c88dda6d2acb0122726238d0cf98aab9e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trino@sha256:6a9c4166fb53961bf6f3d2fbfd2fee7b6ce99ae2c2e875ec350b5458e41464c4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trino@sha256:cc4554b886d2ca674083df23d62e6a555f8af7d4be9821c5256baf941d1b08dd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trino@sha256:4a0d174c6cf47b6628619295ed7f06c9b38d53389470b1f0e9d59e7189095570
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trino@sha256:4b0a53adf9005f2e73d0ef4addb8e2886087da9f5e899c09fb6ef914f842aeef
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trino@sha256:9f81f5bc483859908ddf6c690dc2921f96ab7ae9d80ee9af9cde28dbb230f7d4