Sign inSign up
Trigger.dev

dhi.io/trigger-dev

trigger.dev 4.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips, 4-debian13-fips, 4-fips, 4.6-debian-fips, 4.6-debian13-fips, 4.6-fips, 4.6.4-debian-fips, 4.6.4-debian13-fips, 4.6.4-fips

Index digest:

sha256:0ffae2911ddb2dce2b088a09a22012bba7790f31b92b5cdec6b961adf85a6f83

Manifest digest:

sha256:783ec9ee457d208937f31f773fcd55ea2558f3a04d616346f06ca9a359783f5f

Size

245.91 MB

Last pushed

15 hours ago

Vulnerabilities

0
14
14
3
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trigger-dev:4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trigger-dev:4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trigger-dev@sha256:4758708592953d94a5a00154080f723ae9b3bebf57775c2a1b1ecdca742b2e9e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trigger-dev@sha256:57e7b98f77db25d8a1ef6e35282a376f9fb0e807a85069a604e61cf246ea9eda
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/trigger-dev@sha256:4cba8274657e776737ae2ff2bf66ad813efda4a58cc9e3871282af4fbbccc997
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trigger-dev@sha256:c006938e9566fc161a3671cc606b46d3574755de1c902faa0af5c536603757f8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/trigger-dev@sha256:cf8061ae60b54e1532ee33d8ed07bb03894c4e2f7aaaec20a9f9a3621ae21896
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trigger-dev@sha256:37aa51c0abdca99b0473d64c1f977686c32da19a809989be7fbf6cfbe4a0b35f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trigger-dev@sha256:5349b47b09c7acfedfa15cd1ef5d30a5c5700017309a8d7eb61c5c69b3d5d825
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trigger-dev@sha256:e51b954a627f7b5bdd54be1ce46d4652feb5ea6349aba53bff2608029ed95f98
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trigger-dev@sha256:0c9e8e4202da68c483522c4c65f68702ebfe3be64fc78a58e7d9b50b7895d773
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trigger-dev@sha256:cffebfd487060bf8c23e01c54af00ca244e702ab8ad0f5bf87572f7d75513bd4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trigger-dev@sha256:07b5899417df4cce44aa0e427a8cbde36bd90cf28ec599d7ffc4ba26dc6280e7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trigger-dev@sha256:a1a5543e1f4f478cd8e02126608d1cd6ae8d61abf870afe006ef77d7608c8fff
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trigger-dev@sha256:399d1c36f23920291dcf9e5dbc09ec6f2e71264326abc4769a0ae9e87f1fbbf7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trigger-dev@sha256:dbe635556d197b6704cc30a8451559cbfbeb883a2b987ab97821a017059af952
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trigger-dev@sha256:226da9b237b080094341da2e5f617fb9cde1dd3858486f6334a02710147836fc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trigger-dev@sha256:d5b51bbc7304bc34220da84b1aaae4e9ab4e0fc6538ec521dc75da9f3ed3319f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trigger-dev@sha256:191af05bd7199ce61a8bb65467d854ad11ae004ce21c19f2630adc5aa3e0e739