Sign inSign up
Trigger.dev

dhi.io/trigger-dev

trigger.dev 4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.7-debian-fips-dev, 4.7-debian13-fips-dev, 4.7-fips-dev, 4.7.3-debian-fips-dev, 4.7.3-debian13-fips-dev, 4.7.3-fips-dev

Index digest:

sha256:c625f7b8c7fc1557e9eff0e207af7fdb3189ac0a9f5e767c131b698da08cf1ad

Manifest digest:

sha256:48747e2aa1be9cbd2d5138b0cc8006fab450fafa5483fd105e4e63e0aa2ac13d

Size

278.48 MB

Last pushed

2 hours ago

Vulnerabilities

1
7
8
4
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trigger-dev:4-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trigger-dev:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trigger-dev@sha256:c806f0c89ac60615abfbb8df31e95581b02e6fa5ed04c5695c1959aef205fc26
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trigger-dev@sha256:995f54383e7d5aa76a1e0252cdc39e649a576d1b49c71fb8f58253cd9df0a860
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/trigger-dev@sha256:6da92264ce1e5c38a983b5295f26ff1eb322a26b11e97ee532fe139a2d89bbe4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trigger-dev@sha256:fcaf6d5de0693d9afe39375fff8622a377a2e79f504d28e5481d9c3b2144325c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/trigger-dev@sha256:15c70f655fe130aa3426f0e37ebd4f7b39c43924bdc10558b646c325dff68ddd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trigger-dev@sha256:189209ffc59a533f61f72e8d005b410c540e28b92810c0d8fcbd7729f2576178
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trigger-dev@sha256:1ca2c4bd7c6f078620edaf8a798352cd4aa6b4a224e9d4efd9b54c41e003731a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trigger-dev@sha256:be7c980d3e07fc6505b449f98e2fedd407efcce84f06acd2fa2141ba054787fc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trigger-dev@sha256:6211078e75f1d07c9c656246c4d32990a0bc48c6d7a42e6a7f853afa8ebfcacd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trigger-dev@sha256:d5c48b1ee4b294ac75715f90410a8552c6909b80cb5dc68e759b16819b50d7c3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trigger-dev@sha256:2f49e4950735a10a56a7852bb98a0b9d6e97c9473224df71c6c3c9a0a57b983c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trigger-dev@sha256:c9269a7b791e4bfe279d1870baaf357e902969c67c5e28d1283a1c9ae3d8ac0e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trigger-dev@sha256:ae90ed2d547a36ac6ea8f695fadad5d6183087d11393851400aa798a91cc9d91
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trigger-dev@sha256:bb0721cdfdb7facb446055b3f9d1bc235f906686ece558efad6fb8b0bdc17d6b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trigger-dev@sha256:a5b8f2a6b976e83fe0ccb272f624656bc85e63600dc69da6fdb69ff99bcb2288
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trigger-dev@sha256:ee5c7658ce7ba2f0a84de6347b095d119ed9d56d14b56abb73fa59be27af0316
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trigger-dev@sha256:2d52f2b85416440919a74b7abc792497f9e33407274408c53af387d77e1fa2af