Sign inSign up
TruffleHog

dhi.io/trufflehog

TruffleHog 3.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

3-alpine3.23-fips, 3.99-alpine3.23-fips, 3.99.0-alpine3.23-fips

Index digest:

sha256:bbf1bb6da763360b9f05b64b41cb35bbad6ce48c53c76012543049c93c4afedc

Manifest digest:

sha256:62b25f540cde8cbb5ec6207190848729c8edabcc6e69148ae5cdbffc05e506c4

Size

36.15 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
1
0
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trufflehog:3-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trufflehog:3-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trufflehog@sha256:44e917dd64e1ec1c7f233dbcabab4e0a39ff01698345f784c30617e5ea15cf33
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trufflehog@sha256:9293d21180e19695d794cf90f193bba35ca3420e4ae186d044c12f0937eea143
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/trufflehog@sha256:6458a7eedd3472a95f38ce56c33f4b8d9cea5a45ecd8af1c65bee174b50cbc4b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trufflehog@sha256:71ee9977d8fd5b4b6f628df0fcc33d794c1f33cf1cfec92512284333aebf99fd
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/trufflehog@sha256:8a04393377c6eebd53f7775adad16ec2310af901797fe1cb60d190457f468580
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trufflehog@sha256:9fe2147ef7fa1cdea9b7c69bc1c4b7e9fc50e95626aee542f1fbb5557dbd8c1b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trufflehog@sha256:effdf28926870f465c0812b2bdc02f3dbf3ab04503db113c44c067ff098e2cff
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trufflehog@sha256:85745b821402f40613c60697525c97671671ab5878762a0a503192a79dfdc358
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trufflehog@sha256:2db0ed9c95a3d721d0ed8db8adba2b8002a9d0ffc6e47c8d9661ece031643d81
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trufflehog@sha256:d808f9f85e8f104686ad97d9dc7f98d85f77ae7789042eb812a46865afce67f9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trufflehog@sha256:e030889df8ccce761770e91ceb3d3d178def27b7a974289f9d4bd8fa9c901eeb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trufflehog@sha256:01a5a37819c00038e2abe1e08d176e1517649f8aa855a9ae306f66a6b7588999
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trufflehog@sha256:0d7c056adaaec9877e2aa60e3add98587fc2284a08d4e38e40e81aa154914104
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trufflehog@sha256:d4776df92f597397dc3ac811884f4cafe17ea05f24f2046312cd3f4f1613247a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trufflehog@sha256:332c17afdd0408dc4d758154e16fc951d9887042195b8e7ce3f88b8ea20e72e0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trufflehog@sha256:c7975358c71913be5cfdda327fc340cec63cd7363cfd8f9616c2eb3a10ebf622
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trufflehog@sha256:97c45b8a6da607a2ce17b42158b51a71fb1dc1e399c6eb9ffed133d6105d3bce