Sign inSign up
Trino

dhi.io/trino

Trino 483 (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

483-debian-fips, 483-debian13-fips, 483-fips

Index digest:

sha256:0098cc2292bdc262e8b32e688942de7d260ac0414c0f9fa675b19813f2ffd1c7

Manifest digest:

sha256:5def3d189b675f13f49ea689542667cc9ea8d2e9cf5cdda963c431abf011f737

Size

302.27 MB

Last pushed

23 hours ago

Vulnerabilities

1
8
0
0
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trino:483-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trino:483-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trino@sha256:574a1bc2952d649b7156b6e98ffb17cce2fed64674f9713e4256364527b6bb68
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trino@sha256:7ca2a8a6b6168e7093a493fcd6b92c7a15d4eddc608bb0999b53cee34d2198b9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/trino@sha256:8e66cdd1dc99d5edf2bacaed0725510803bf3726d753eea345fab645d9aac5aa
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trino@sha256:98d40697ebb4779c929e5b560263316d2d730df337fb9b19a7095006929541cd
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/trino@sha256:18a907e802701942a98e55f028232488e2aea367ad7f404710531939447c1e75
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trino@sha256:1b2139475e16ef2da53fa4fca2a733cedf703c2f8fe6abe680b2285f97977bc5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trino@sha256:a922989fdfa225d77440e456a1cfe1d27be34c7fbb27906bd9b4c3550d1d7acb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trino@sha256:cc59dd6bc10cb7707e70f54a99a9bb1ea910585ab1d93838e0b025b337d2a0f3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trino@sha256:debe4f48f9411ce4f3fc042c4f14ba1e41d35ca33b918dcc0808127e94365d58
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trino@sha256:072cb210886485e616ce90d42aa1b36602568231b3952f0f4f9992271e7d00ed
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trino@sha256:3f1d6cd0133870d4b1ce81c1fa29663fb2f689390681e01b66bfda6cae302a77
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trino@sha256:a502c1c5e207a9e8b59868bccda9e3077172981f6a778fdc14104fa69cb01e41
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trino@sha256:1bd85b7ee4b987df101638e9dbc515e04fe8355fef9942fb154034e2334dd054
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trino@sha256:2f4a6dfdf6fd174abf8e851c8ae3aa4fc37295b0875ec34c94c20bd9ddeff984
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trino@sha256:b6a61ce5982d321ed7f4f2e2683e4bbdfab6dff5bf2ea6f2b15c4be24f03d85d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trino@sha256:a9fdff19bb8fe5d804d288a05479728ff884405c6470c2254dfbff927d31643f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trino@sha256:7ac53ba6b70ee26ecde3433ba93ba175e1fc3b445494ef793ea4279ce6bf116d