Sign inSign up
TruffleHog

dhi.io/trufflehog

TruffleHog 3.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

3-alpine-dev, 3-alpine3.24-dev, 3.97-alpine-dev, 3.97-alpine3.24-dev, 3.97.9-alpine-dev, 3.97.9-alpine3.24-dev

Index digest:

sha256:80b5028e5e513dc729c4a0133e16616a28cca305172d98b15a731d6e7ca28cc3

Manifest digest:

sha256:42cce273f7003c042b17c59f725d0b190bc4efcd7bf6c1574f7ca801fdc929b8

Size

68.42 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trufflehog:3-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trufflehog:3-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trufflehog@sha256:1da60fcb1a50d26cbde317c7138b90bb590acc4ae3c1058d518a9593a008235d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trufflehog@sha256:3e39cb561c6ab06eefde5185079573de378e3d2822d2ea40e8c41a2233e4462b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trufflehog@sha256:007d28be2276ebcbe19db7e7804d567fdb6755969b5c1038d47cf5d6521242c2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trufflehog@sha256:532c0064b18c3eefe853672c567758e707251373da8b84f60b353fcdfff67303
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trufflehog@sha256:fc3d31faf4b2138007b6cb7a0767fb0361c43dd3a2e67a8d1f4cac4b6924fc25
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trufflehog@sha256:1a53a6fb2d8607de1227e8e66f2b7b415185701ead7094dd569dce1475148e46
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trufflehog@sha256:390924d822ff4486bd8548eb6aacc0904403500b137d3ed6af3010b49a6d7b55
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trufflehog@sha256:d9728970293c1ac5f671c687ff985697cf5b0236955b18c0e71cce5a240a1fa3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trufflehog@sha256:0abc6a73bbd4ceee87815c0481c003118964088deae29533129d469ba710a81a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trufflehog@sha256:80bac7f922f693a8a52541e9e9c60a42e34662a56fc2dbf92c3426f6cf2cda5d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trufflehog@sha256:2cb3dad1f9fa43e5fddcd49eef4a2304b0edbcf294d98267016c7041c9c5110d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trufflehog@sha256:031f1c0041e5cb97bafe8de21ad2572337cf9a7fb3b8a8c0ca76b55f3e29806b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trufflehog@sha256:0e07bca1e9a2e87ebedd33582078f4e4bb672702815b18768eab56b509ab476c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trufflehog@sha256:6fefce2e2f82553ef7b6a88402b924b147bd18bf8447616ab5f8477785b2f6f1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trufflehog@sha256:91909ae66843f2cf19feb565de964f656adf4d37eee73423a062e2c599a294ea