Sign inSign up
Trigger.dev

dhi.io/trigger-dev

trigger.dev 4.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips, 4-debian13-fips, 4-fips, 4.6-debian-fips, 4.6-debian13-fips, 4.6-fips, 4.6.4-debian-fips, 4.6.4-debian13-fips, 4.6.4-fips

Index digest:

sha256:a7eb45bf4050627d66403045b26d0ad4e283537776aae9902f2afc92c736bc97

Manifest digest:

sha256:48b9a8deb336d129cb6126a1ab47107e84a191b2492730ae959fad318c5042bf

Size

245.91 MB

Last pushed

5 hours ago

Vulnerabilities

0
13
14
3
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trigger-dev:4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trigger-dev:4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trigger-dev@sha256:cde4f5744c4c19d65dc4f4d9292bdd01ecaada9ba9b7e8665d623193d039dc12
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trigger-dev@sha256:8ea415921676b0a63c299a608996de9d5c8e310d6174e06538bbb12918e9205d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/trigger-dev@sha256:70bc578d25518e705c420d4d448c601d209d5041c9faec2bd626b3d4abc7fff7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trigger-dev@sha256:e9e27b694e4810e4ebbb2166614a6268423578504bbe17d8ac93063b1f0fe475
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/trigger-dev@sha256:2f4bfa9db652260b5ffeb7d76fbf267a23cabae970eb190b727a5578c84dec26
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trigger-dev@sha256:4b67f9524ab397ef6c0d4118eeaa37d7caf22960bb63b39f436619a2eb9a0374
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trigger-dev@sha256:43306d2a952d01080fb8fa5db7a0f0e552752270f03e81c819d4e65f5b591e3c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trigger-dev@sha256:045eeda7443f09f8af68e028db1afe6b123aaa5d297e22cb751ce404f48236b0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trigger-dev@sha256:6a1cadac426531a52a47aecd3675567e3f1d6e0c2ceecc3a1c576905168a9a8e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trigger-dev@sha256:312b664e7da14467726fe0e699cbc19564242f3ec4f91e882f5a8611987c2a22
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trigger-dev@sha256:4ad212e5f22062804001c90a3a68b519810e982440a52c5a23a6b3f388d5ac58
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trigger-dev@sha256:e4024ad643204ab4edc0db6d72b7f67cc51455512d28147e3c08770e1ef64ec8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trigger-dev@sha256:0be0d5a2896239ccb1d6a58b180e28de257dcc92512576f59715ce29197cab6d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trigger-dev@sha256:82eb751d43fc1f3053dd57732898e98b65888482249da66722a8fb094a7e940b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trigger-dev@sha256:674740145deb57c13d86d44efb6ad6bf9946d4eca8bcf4f6b9a70184fa4bd6d4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trigger-dev@sha256:467d51fa23606bcdf95f59e59c1d9d1ffe42d3c0e6bbf0bd52e9e008e79cac96
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trigger-dev@sha256:ab2cda1a316c4dee4ac14d356e3e01966ed6022785db9df6c9f370bbeb3a2ef9