Sign inSign up
Trigger.dev

dhi.io/trigger-dev

trigger.dev 4.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips, 4-debian13-fips, 4-fips, 4.6-debian-fips, 4.6-debian13-fips, 4.6-fips, 4.6.4-debian-fips, 4.6.4-debian13-fips, 4.6.4-fips

Index digest:

sha256:2930ae20562bd17d0a1e257162258fa042365385285b79ff0cc306363802c746

Manifest digest:

sha256:dd837acf02dd4b71945619c41544c6c44d4f38266264160d7936506f27c3751d

Size

245.94 MB

Last pushed

20 hours ago

Vulnerabilities

0
13
14
3
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trigger-dev:4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trigger-dev:4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trigger-dev@sha256:6fe089f90c2a40ff1ea53301759e37a2c55c21611c5b9dc4dc4963f8a88f2943
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trigger-dev@sha256:ce76733cf00cddaf2f1dcdbc3342e0d56d15039502c0c9af2624c1ba194bb3ae
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/trigger-dev@sha256:3fc719ba8e8acc16e8ca9f410711ccde0caa4bcc382a04218d5419e6dc9a8c51
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trigger-dev@sha256:6fd2aaa40366e3bff39105136e9e59d08533949abcc770e36f63e54d2d922b08
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/trigger-dev@sha256:4a497da700b762368e9ab295ad2f188a5905ea46bf2a3ecd57ff10cb5782e334
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trigger-dev@sha256:2ef2477af0b0822f9556df390058350e19a0633e084070cbe49ac09f1bddbb1b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trigger-dev@sha256:dab6f72ea8ae7ac74df957cf3e7719d2164ab6ca225a5bed587ff22c7430a64f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trigger-dev@sha256:0cf55e58701056e6684d7a8a8bdb8e26c7016b25fd1a875b1626ae999896d553
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trigger-dev@sha256:74c3d05a2735d662eba45930e344fb04ce66c145aeca4744463c4d4b7fc1ba3c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trigger-dev@sha256:999df89a35e73ee253fdc7613e368d43006b5dc1bc0eab43472b4c8c940ed3c4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trigger-dev@sha256:57f90ed2769bb33d38b9462ab0da99e213dbf29aa39596ddf7143024cd94cee3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trigger-dev@sha256:15312518b6e84d6bc1765050e53e2b60662b0112a2bbfee9a705aaf551404c47
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trigger-dev@sha256:cbe041e536c72a0440900b7285f08cd2e113659b6e5680136b76a1eff6cf2a3e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trigger-dev@sha256:c39dd0e640c3e418c3ba60b04228c5f7ab3c5d3324dd482f5ca07ac98112f519
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trigger-dev@sha256:134148f4723aa1854dae23877930146bdb5ba3add53079ed6312021fc0fd6afd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trigger-dev@sha256:146bf3f67f240fe02710d236040678fb010e6bf101ec1e8f96e28d2dadf4eb73