dhi.io/trigger-dev
4, 4-debian, 4-debian13, 4.6, 4.6-debian, 4.6-debian13, 4.6.4, 4.6.4-debian, 4.6.4-debian13
sha256:80b8d5b6d895b641d3c91653687ed7d5c68186809530816b6cee22f98781880d
Manifest digest:sha256:519e8bd568259ed936175739a1a10ab23c2028a4e2adaaae68d6aeebfdcd5b8c
Size
245.09 MB
Last pushed
8 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/trigger-dev:42. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/trigger-dev:4 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/trigger-dev@sha256:0082b0be84142e78de6ba1b1a079db0b58eda5561609f16abfd012edc7defecd |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/trigger-dev@sha256:659221816794632ff70e623fd7eac3cc5a679c6d941423c2ef752cb779a3d3df |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/trigger-dev@sha256:5984c2e2fa455cd66144776e0e3ba428313f1b72f901b9dd2e6636522336860b |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/trigger-dev@sha256:e3e316315899fb6cec406299240c6e96fae412301304acbc3b85d7a9432f1ae9 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/trigger-dev@sha256:8baa8e0bb13a5eb4dabf26b3e42d6f1b2c79389abf1c6ee877f019aaaba5886a |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/trigger-dev@sha256:12745f264a6d126171b3e7102e5f278711553f9cceb29c30a9d65d982c669214 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/trigger-dev@sha256:dbc8e4cbbba358658a620d13a2d6abd97f20f9eee083dd3d184af966c1ad2bcc |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/trigger-dev@sha256:2adf14ff8e7657ac2c63faa4b3558d837ce0e0a36593bf5df189585e7856e073 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/trigger-dev@sha256:67002bb83eaa744458bfb51945a53d73925df7480bddb7d6a3bbebca1fdaa77d |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/trigger-dev@sha256:ba43c0c4bfe5ca9e530f2e3f70e631986374b1c3e4389b1375b6ac272bdbe463 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/trigger-dev@sha256:118f46e6944f7315ee61f3dfe289f637e9053765ab230ce827f7e437192b5b00 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/trigger-dev@sha256:50d11dde9ddcc65931ddc7ca6e5290a6c1acc35d49587f7b0a44c4f2a9a24ebf |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/trigger-dev@sha256:4870996215dd7596f7e7eccd3e06cac47a1112df2ddfb4817dc820f81537a968 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/trigger-dev@sha256:e84260b09d5710aab0585bd8ece912872acefdeb3887b2b19da7f39b5b15d79b |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/trigger-dev@sha256:fed28b21dcabfaad5132ef52af1b1ab7f5a009d2e225b05246728bdf750127a6 |