Sign inSign up
Trigger.dev

dhi.io/trigger-dev

trigger.dev 4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.6-debian-fips-dev, 4.6-debian13-fips-dev, 4.6-fips-dev, 4.6.4-debian-fips-dev, 4.6.4-debian13-fips-dev, 4.6.4-fips-dev

Index digest:

sha256:67ec666682fe9ce6fec753b1adfe9d6ea8af5b1d94684bbb2abb1e5c26248af2

Manifest digest:

sha256:777b1cc0f5647e30b316ebae2eb507334795e36318491f8db87b2dd03985df87

Size

273.61 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
5
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trigger-dev:4-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trigger-dev:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trigger-dev@sha256:c57550fb99fc77209b7d6a657422fe1bde37c455a0595345c4431c0a1e5f401d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trigger-dev@sha256:23aeabde7f7eb79a5e2c0035142f346f7db8cfcea2c678790f71778066c24d23
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/trigger-dev@sha256:9c3135d6991c41e751c453b3ecb959b628d3e527cb9ca7ee436fd2eaf8ce6062
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trigger-dev@sha256:c05a2fa813ef84697af5935e8c5c116f07f913f9c48a40e4d73c22866dbb55a3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/trigger-dev@sha256:d1fd5b315604d20f4772c46287e9971ca3d5873127eb2f5a52329fa5442dac01
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trigger-dev@sha256:943a42308b765ce0211ac01221d021f2a76bdc9208aac1a73da5ee565fbaa11b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trigger-dev@sha256:eebe36b3458e4b51334fdf79524480a7120ca6b76df148ed8384fad1921c7e76
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trigger-dev@sha256:6dd79560781ec696031071647bd427a2a0c7a6b8dba4f9b30f932c577f65b705
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trigger-dev@sha256:888ba1f8542d0978e77a70a8ecc5b1e5760cfa0967fa4854d0a591f2d1741678
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trigger-dev@sha256:1336956c9eea8fa9d26a2550890cff5c4284d788d416c6529f65fd012686d250
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trigger-dev@sha256:57364c7fa232cc2ad72833860b939e1f88e6d0f66ee2621c878fda9678c33f83
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trigger-dev@sha256:d415f04b12c3edb2723e167b7634a1e4743e0f6917f22ce5d875e99e4f8a7324
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trigger-dev@sha256:06ac2968b1701f1ef9d05ac9bb32af5fcc2de643184319b9045405fd5cec9043
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trigger-dev@sha256:3471a7b4ffd2ea3491e0438ec26c753a6e32e33bb1d376f83fcfa44317831e02
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trigger-dev@sha256:58d27e6e8cb96390e7cfd7a9c652da4a7b7bb44a30bd136d70b181a6b158edcc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trigger-dev@sha256:36e9129ecdfd42bd49784caf2e527be0113c65780604312ad49878c4acbcbaa1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trigger-dev@sha256:196353867ab1bd5a165d2d52a9a62a3e22cb3be279578e6820ab07dd7b011984