Sign inSign up
Trigger.dev

dhi.io/trigger-dev

trigger.dev 4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.6-debian-fips-dev, 4.6-debian13-fips-dev, 4.6-fips-dev, 4.6.4-debian-fips-dev, 4.6.4-debian13-fips-dev, 4.6.4-fips-dev

Index digest:

sha256:2ccef049b37f6a2a89aea2304685412a16bc19e2d1dcd99b2622265ac710a7d3

Manifest digest:

sha256:35efe16a3a09eb4125ea7429cf65a2c8853ce877261cdccb7b2da9a9fe20fd08

Size

273.66 MB

Last pushed

13 hours ago

Vulnerabilities

0
13
14
4
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trigger-dev:4-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trigger-dev:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trigger-dev@sha256:117ca2379e1f5a8d021eb7b45548c98b29baa278a997a833928b1c6dba35e6df
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trigger-dev@sha256:e4966877aa3dae12dfc818c48110f6f1b7b1d3eee7c14dd7ed64b8d7fdcb1282
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/trigger-dev@sha256:92126bbcb2568c118624f77ca1d43a9eae6f9d86e48a78f6fbd40766c47f9da9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trigger-dev@sha256:515308403da09b4fb07d4321c1e14e2d2dcef3626eb7c51ac627cbe96559e3ff
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/trigger-dev@sha256:68059cd0306e76dd3b097757a384b97b59d7bc02b6cd8009b77cd41f7d874915
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trigger-dev@sha256:33dc09fd9e95b250d40ed29297487ed2ca3b523038b181544fcd45b0e7820cb7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trigger-dev@sha256:68c2c692ee8676c20d8034f901e4d5597eea0b9e4c64e7c00d27df4ae481a76a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trigger-dev@sha256:c7b41252ef1b32a64135cfd674e9bdea2679c1cdadfe41da14d881641ae07685
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trigger-dev@sha256:51b8350b5f6380128df79fac751db8982f754496cbf9d65d61430673b04717f4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trigger-dev@sha256:5d6f0628f3f41519bdc7012bc435c81cd32e8a44eef4af2facc930385fc2eb7a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trigger-dev@sha256:385aa2d6ad4967278acd405902bf6d902b3c8bb47167d862cc54a3643c981985
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trigger-dev@sha256:35ba23b87464985e66dc4bf5cd41b3f944dc103c541afde7b71a1e776d008cd9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trigger-dev@sha256:7db0d1292f8f346c8c5358b1ea9413b826a8208fde87bbf01db61241f00a80d3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trigger-dev@sha256:d69ebdd65076dd120da7f67b4f5913d8f59633684b8fddd38dcf7e16fe116a23
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trigger-dev@sha256:c535bcff6e7e453d003e8b12e293a1743a4dfaa8f8742bab46c9f5a8b4940b2c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trigger-dev@sha256:359031ed461c772770e10386bd76cf60e604b6fc825b08f606f34b4cd3b40bf6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trigger-dev@sha256:e8bfa2b71342bb400cbf70bae4bccd60dc4480addefce25b2e27914262b4e0de