Sign inSign up
Trigger.dev

dhi.io/trigger-dev

trigger.dev 4.x

CIS
linux/amd64
debian 13
Tags:

4, 4-debian, 4-debian13, 4.6, 4.6-debian, 4.6-debian13, 4.6.4, 4.6.4-debian, 4.6.4-debian13

Index digest:

sha256:6ba2b1f0ba351dd5342d697f34d0e2ff2470316c7fc86ca340da6e050b0bd3b2

Manifest digest:

sha256:ac3d7e64f14ca0e18db2b20ca91d620d746d6b997d325dc7878a96853493a95a

Size

245.15 MB

Last pushed

17 hours ago

Vulnerabilities

1
15
13
4
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trigger-dev:4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trigger-dev:4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trigger-dev@sha256:4b649cb1198fbd34cbef305d3a24916416ea2840c7b8727bbf2fdcbb8dae1622
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trigger-dev@sha256:ea070b33867ce65fac255a45fda764377c5b76146752d0773a967d2c3302064a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trigger-dev@sha256:c73a90ecd10adc2bdf48830fc6bafbd6c0c10eb0639177a79b82ede305cec59f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trigger-dev@sha256:634cc871def535eea8899f3d316c4e296f0b3c11a9acf9cf8724b7536ab5377e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trigger-dev@sha256:6d88b6f962e5736c01f47a5f2fbf24aab9cf50eb443aa80ac8b2fc3fb600a9c3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trigger-dev@sha256:fe55ca9a72dd8799566f367014950fb7b2dd7278139a26b1ec198b1ab141361d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trigger-dev@sha256:9b31e3be44731542b508cb11976fd3111d27fdcb905592ae7572e3caa533d97c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trigger-dev@sha256:b6da8fd273334448307c932327418904f49cf7f389d606f3539d74936419a53f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trigger-dev@sha256:f8b52990210af865b6b236059053c199a551e7b7d21f91f69b03b427f1b730f2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trigger-dev@sha256:ebd12e4786e370a43fa04b46a83422b796968ed283d93d077afb9ec5c7e5d325
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trigger-dev@sha256:89996af02ca3f73d51a2d6e9f73bf6466fd7187a5ab04677b2c92ddd39a6b4c1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trigger-dev@sha256:587629b7186f25393987b50e4056361bbfabaaf90f48f62460cb1a2bfca57230
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trigger-dev@sha256:c2d9e934a76f6d6a73ba12e87b592967c68e844898899bcae7fc76f569a88c9e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trigger-dev@sha256:ea9679c4a2f6c631bdd3c61c55f89c2d34753d4304aca533fd5e61dd88ee4bca