Sign inSign up
TruffleHog

dhi.io/trufflehog

TruffleHog 3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

3-alpine3.23-fips-dev, 3.98-alpine3.23-fips-dev, 3.98.0-alpine3.23-fips-dev

Index digest:

sha256:f09e822ed26516a208cb6a0f40cb204c0fd93fa6dbc0fb8d94757b01b86dd084

Manifest digest:

sha256:6fc27ec66a30b0b196382aa0a8c1ac82c32dbe9ca8a25f19ece8036ba7a96640

Size

69.30 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trufflehog:3-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trufflehog:3-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trufflehog@sha256:1471c46e9f6e961f18ec38fb739a3eb65bcdfd4a9eab698f64e69040639bb472
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trufflehog@sha256:e7d04ed4ba7ce14f19f0aad5755b46745cfb4a8aeb96a3676c57ddafa33fcfa5
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/trufflehog@sha256:b441c5180a86f21ad6a98cf045cf3b7a6edfe1fa9d80eedd5bcdc4ed6d9a836d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trufflehog@sha256:a0dadc2de723091354947b9e635275713b03ed260f21693103f97b5ee039cf8f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/trufflehog@sha256:0d2be976318d4387c375068ad06bec738b5866fa55f4e0478eb5a89c3685c6f5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trufflehog@sha256:f4361c6a187aa3b4dd9114c4a6a94b49212248ba5b728156f7c5129865de464f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trufflehog@sha256:23e10e2ad720f718cf177487dbeaabad4049cd8d8efd6a0ee9ae239ac4c4408a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trufflehog@sha256:424de9b01ab6325e9c45f1a6c5258e53b2d01a8320b08d03f99e99a7f804eb67
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trufflehog@sha256:f40a28867958ed15d60ab7e00ff403d42be6a72ef099cdc4eca0fb0d0c7da532
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trufflehog@sha256:91c3b7241c3355b6c26514bfca11ae5830840fd0ff07769203790f2bed0fe1d3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trufflehog@sha256:d29c12c838e6beedaddb75247229c3a7c1d5a3c8f8bfa771a57db59c0e8acd0a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trufflehog@sha256:5fd25576341873beb7f579912ec1133b000ca42d9842c749d0c97543e7f4562d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trufflehog@sha256:334faf047ef624c1a8beb89ec9bf1dac1677f9be00e7e2e809f94279c6c0377c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trufflehog@sha256:95daf24ffd166c69c6badb5a648385ad567b653ce20be84631d4556e5b62a05c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trufflehog@sha256:13f71cc8b39f1f6b3873707c800e9e06a3ef29f8f1116d7e6b3fa1cb8cecdd73
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trufflehog@sha256:26a996437f7bbb3e4d99c5aa168914e5c75db367d5d31b59fdf227f3b6b046a7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trufflehog@sha256:72d232e060545f054b103c7e3368435914e99978402202be363da7a939ab6602