Sign inSign up
Trigger.dev

dhi.io/trigger-dev

trigger.dev 4.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips, 4-debian13-fips, 4-fips, 4.6-debian-fips, 4.6-debian13-fips, 4.6-fips, 4.6.4-debian-fips, 4.6.4-debian13-fips, 4.6.4-fips

Index digest:

sha256:0acbe3666675285b2e8254c5935ea218d4acb5eb1e80ffb2fd22b5f41175bf65

Manifest digest:

sha256:9bb1ce1b9abab85f88a9c4620c6153fc27187ad24c5a9b27693971c7dac6d67c

Size

245.92 MB

Last pushed

6 hours ago

Vulnerabilities

0
13
14
3
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trigger-dev:4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trigger-dev:4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trigger-dev@sha256:c0784e131c7e5644f0d350bfadc244030d0617dfb8483ae863fe4b732c43ff0b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trigger-dev@sha256:5f6b7c6781f4a997e13fee3fdfd4891ad1b70c1932ec2c14e4ed865211eaf1fb
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/trigger-dev@sha256:3392e20ae70f2a96e5b01f9410b38370dfd445ee90e32155ad3380f5ea243f02
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trigger-dev@sha256:a1a4d7d8c6cffd4147f929a7627a50e51b97fa71bac3811a603beb276b51c522
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/trigger-dev@sha256:706dc7978ddb3f5ac962911fab00012c3016d0003295039bb59345dd328a8164
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trigger-dev@sha256:a9f3f08bb6838f44c5c9a207df0ce3ac207c7e75297819cee5930818cfc63c5d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trigger-dev@sha256:42a85f2802f92d085fa00244bb23cb5e0879ad3ca3aeb0952bd27b2ea40aa044
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trigger-dev@sha256:dcb1a1b773bd74f6aaec95fddefe769c3bd57df2ddc3d2d209620fcd1f35d235
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trigger-dev@sha256:3c0c105b71e7a70610b0c9bedb44aa5724baa77f5d80fe3a757d001ad94f6c6c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trigger-dev@sha256:0cab42beb51960e63f78cb02571df39d5614b8a742b019398887046c3498764a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trigger-dev@sha256:6d75b8812ced19df7e85403bff1c4a2ae12b5c62026212d59a9c7e0a4683134f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trigger-dev@sha256:76b1346f8c70dabaa118d585d922eed02a9231f6a0d04d93cc17d385fb8af6e6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trigger-dev@sha256:c583fa8542969bf6a27ebdcc16bfe34c48f8527ab9d440b1ac9ff755c14949bd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trigger-dev@sha256:cb07ee7c080fc33b8df3722657880b5e95c85d3346a4507e243e554d7a8b5ddc
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trigger-dev@sha256:286ceeff7afe95c515e766c252b99811c6acf7f5950c90bc7040bf1614d5e3a7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trigger-dev@sha256:b4f8ef6ec97a736b041291c1333b69273b9d0e849ffcb80fd845bc609bc280bc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trigger-dev@sha256:0f7511ece4c321439aaf5b17c95c35f534cfc9a46fbaebff24f19beb698bff88