Sign inSign up
Trigger.dev

dhi.io/trigger-dev

trigger.dev 4.x (dev)

CIS
linux/amd64
debian 13
Tags:

4-debian-dev, 4-debian13-dev, 4-dev, 4.6-debian-dev, 4.6-debian13-dev, 4.6-dev, 4.6.4-debian-dev, 4.6.4-debian13-dev, 4.6.4-dev

Index digest:

sha256:ac02a74a31a0728c6a0f04c999cc3125f31eaa9ed7cacf3173a5b13857bef01d

Manifest digest:

sha256:1c6d51c3c38be847905edec01831dd0dff9c7574a32e9f282b7e2843df19975c

Size

272.85 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
5
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trigger-dev:4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trigger-dev:4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trigger-dev@sha256:35b891c7bbf856d47ad289ebfc67785c4de51b68272c007f1bbe652a6539530c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trigger-dev@sha256:c38061f1bcb510dfbf4704b151006cdf47d1fa04e8ec10f28d93a0df8224023c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trigger-dev@sha256:2db7efc41b0902e75a571f5c4e30b09ebd2f026e9d9f44726f93c58ea86c93f6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trigger-dev@sha256:ce29e68f2b43599448238ca460048dcd13b3958821be8184aafcd33bfcd1246d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trigger-dev@sha256:96a214cdd962ec8a6f094c34a02b34cb6b68890c31c38ac8f9c84a525e7ae176
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trigger-dev@sha256:5e21b19ad8f9394a9a010e9945937aabc8ea34c1c2a11c96ac400bba7a0baf96
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trigger-dev@sha256:d1213015bb74bd31c35edfd7f6eda8fff4f8e2c98933406a3349c3870bc8e58c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trigger-dev@sha256:1dced470156da7392d4b66b56bbab23bd1dac351c799bfb5503d1c152ec47702
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trigger-dev@sha256:e13174ac4958ca3221861c47361cadf7483cf3f86d60209a789fe702723e8693
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trigger-dev@sha256:f4b165714ca6359ea3414252c2796ec42316d07d0e468c37fbcc7920190e6820
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trigger-dev@sha256:1bbe494706782eafe2cfe35e42b0dedcc4a8795ebdd1a027dca82f7af0db353e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trigger-dev@sha256:58645b804545c1d90f09da835a3c2c43cd73d51a7b0ef5551c513c30ef82c783
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trigger-dev@sha256:242dc7106b136f32ed5f7e3367ece551f7a0ce223181f08cba64faaf6a3a1db1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trigger-dev@sha256:50d4c1aec8d116b0c608122f422bd3275ddd65158b51abd72155e658149c968c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trigger-dev@sha256:74849201b61995de9a3237a2f6b8f708b883b79a124eb9d30157c96446cae5b8