dhi.io/trigger-dev
4-debian-fips, 4-debian13-fips, 4-fips, 4.6-debian-fips, 4.6-debian13-fips, 4.6-fips, 4.6.3-debian-fips, 4.6.3-debian13-fips, 4.6.3-fips
sha256:69db7d8fe48e8c4077b56921c2b7a79c6fe6130687eccf7d1981da545127d9c3
Manifest digest:sha256:b5263d01111ab84ca05033ea09d100c9807a50e76abe0a61ffd49c0aec15b7c2
Size
245.90 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/trigger-dev:4-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/trigger-dev:4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/trigger-dev@sha256:5bd852ea64dd1434f2128005dea4a8c31bd0a29fa8e6a1c729a5ba9c2b5a5fe7 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/trigger-dev@sha256:de29e4d6beab503cee879ba2145a5a673bf30d8c08d3e896204684c0676ae4a7 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/trigger-dev@sha256:09b254e310d40960389f82d5aee4c327445f9157d7805640b3c103918478d6c5 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/trigger-dev@sha256:b039e976f4e2c6d6c3f9ca8d9d94dcf0119578c5f081b7b7db82929ed50e02f3 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/trigger-dev@sha256:409595bd7e7ad676c554da5950beed7115ca7ce33314f68d35c735ecfaebba08 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/trigger-dev@sha256:ac7348988ead1d87e5cb4661a42d0051c8524ac9a4c8fd291c1b6590e11a8780 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/trigger-dev@sha256:5a8a3e461fa84e8995100cc68fa7f00dd8991a10c7153b41abfdcc0d9109d838 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/trigger-dev@sha256:beaf940ac230b69b27616a0d546acc2d2a6b63db563179dd52b4360110d4a191 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/trigger-dev@sha256:0530652f38eaf5cb5cc0b64d2f969c1792961ca05c32bc182d62cd9e47240288 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/trigger-dev@sha256:5fb1094add00ae2bd077d64b0e1269eb5396a0fb4e00700b416af992cad03d3b |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/trigger-dev@sha256:572d25fbf397f130c1b3ce03e54e738ccddcc3e085df5438a7e6a100dc53eb0e |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/trigger-dev@sha256:56e07ffcd1f07a4f9ed0d43c53babc8b6208868e8707b0d40a039ff8cc0dff58 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/trigger-dev@sha256:f0ecab3d43a585f6b9950ba381e7a7f096056546403cf5ec974476bf3a268133 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/trigger-dev@sha256:4b62fddab7dc4a7b5ff915ea84ccd562a4191480827f6d7b01cd440cd106f85d |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/trigger-dev@sha256:ee08b3967ebdb571e4c2a815268f0ab19dcc1e08f8089928fbbeb910292f177d |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/trigger-dev@sha256:de1bee1a2e469c610f80dbb15366bfddbb320c4b8808faee27b61d2ed53b2a08 |