Sign inSign up
Trigger.dev

dhi.io/trigger-dev

trigger.dev 4.x

CIS
linux/amd64
debian 13
Tags:

4, 4-debian, 4-debian13, 4.6, 4.6-debian, 4.6-debian13, 4.6.4, 4.6.4-debian, 4.6.4-debian13

Index digest:

sha256:45cc2a0c34ef98dbbe01631e17e6fde8d9fd2b774631b57b83137bfe3b17101e

Manifest digest:

sha256:ffd39d5b3ad23606a5755956fdf8a6285ce8dd7b2a6aae903933c911ac32b039

Size

245.11 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
5
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trigger-dev:4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trigger-dev:4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trigger-dev@sha256:98c8dc96761b514a5f9d59cb9e7339648d45a9e96c25f04ab9cc21f1088a5154
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trigger-dev@sha256:def2c4db20e6b7e5c9fdb0605717128ae614c7a528e6d7932f9f15c7472444b7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trigger-dev@sha256:efca2cf6822d287f664a714468235df5278929600be508adae308c6b4a453a0f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trigger-dev@sha256:5940a95992fe0c97c56cf77286ed5b62c252135d8050f2fbeffc04ee34950df6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trigger-dev@sha256:c08caeef90c0645a720cd00dd480e44bda316908422d3400acd00404f6ac22db
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trigger-dev@sha256:f22e0db3810bbfcfda1c23806ebd9126f4bfed296a5c1526b334ab282b527de3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trigger-dev@sha256:651077573066b1bde3af8d8463ea48c5625049f335d8dc0511baf581b5f6634d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trigger-dev@sha256:0a9fce9fca6c57faf8009475a8da0b983c09e25888953a1307b6d3346a758524
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trigger-dev@sha256:2bf315c7afda8532ba50f4a2389f0ac7a2c6facf52f8f36cc4860e73b54c320f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trigger-dev@sha256:1fc853070bb7879ef14a1fcef43ae1555630c5d87c6ee2c44e3e5bdea843aa02
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trigger-dev@sha256:73041c0d75e88accd5c1e326a326ed417e1e9d62ee8d2fa882d9b3eb55857923
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trigger-dev@sha256:eb46a817cb7b8f631a6e7dfd6523124684d272479aaf70bbc0d44aebac4520ae
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trigger-dev@sha256:a9f5c922ebceaeda48577fc2a3aa723c9781e1dcb39b625d5302e2d672e1a456
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trigger-dev@sha256:116083803e6a02a67eba4d0083dd329237452e8c18d847e121361fbe72c90fc4