Sign inSign up
Trigger.dev

dhi.io/trigger-dev

trigger.dev 4.x

CIS
linux/amd64
debian 13
Tags:

4, 4-debian, 4-debian13, 4.7, 4.7-debian, 4.7-debian13, 4.7.3, 4.7.3-debian, 4.7.3-debian13

Index digest:

sha256:96fe11cf22b2b3a50bd88c883ec1d7989beb5b61b1e85fcbb83788ac86cb787c

Manifest digest:

sha256:1fc65185e8ae7c34b24c74c778ef3a081d5ae666df8e775aca4e5059a004c0e5

Size

249.97 MB

Last pushed

20 hours ago

Vulnerabilities

1
7
8
3
14

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trigger-dev:4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trigger-dev:4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trigger-dev@sha256:981c62733935fd0e0bb7a55cdc1f82909f23c09b900f0782120c201478b4213b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trigger-dev@sha256:c1be33d429d5e2f9ee9ddda21c33e40aad2d6328913c419c817d97c9cc8f80fe
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trigger-dev@sha256:1b466740ec3fa55bdc841c1c51e7f243d0f2ec99debc5f9f6f147ef3a5c34aa7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trigger-dev@sha256:cc2c74efb898e7cf057ee1762aedaf99896d6c39d26de3c31f933ca08295d27f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trigger-dev@sha256:e8f3b6c04f657c149197cfe271dcf50b282dd6a37d8929a7e1a96dcf82dc24d7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trigger-dev@sha256:795a9002a79e6c029485f54775c8c88b64b1c578a743005057c00760e7632edb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trigger-dev@sha256:bb75f8a7b7441baeea0b21f6b5c8fb82a292e4399f91fb7b11292e0da16dda70
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trigger-dev@sha256:4245a9b208b258b3ef84af3dc00e878ca93e8c15757c0bf899074f8d075f5330
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trigger-dev@sha256:a3dc4781278d116ad36c8f2a33aeb946f271ea079ef87600e9064e1a44b53efd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trigger-dev@sha256:6971a4e95eff13ffce2ea979ba022d297ebce5c5a10df9ff9d67bc781d677c9f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trigger-dev@sha256:5d72fba404e93807ebc9cc1ba47f807b0c624bf5de7c1ff6cf12e92340273f56
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trigger-dev@sha256:5266e3986381a078136d6bb82e1038b56f59ac354b302fbe79e0df273b0d981d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trigger-dev@sha256:627f1490efa816bb1a6165e1b0c4fbb0cfde79b214763a6f8c7575089808b1e7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trigger-dev@sha256:99b32ed9bacbf063e0b62164ebdbe070d9527db52fb444cb2c36ecc5346b9bbb