Sign inSign up
TruffleHog

dhi.io/trufflehog

TruffleHog 3.x (dev)

CIS
linux/arm64
alpine 3.24
Tags:

3-alpine-dev, 3-alpine3.24-dev, 3.98-alpine-dev, 3.98-alpine3.24-dev, 3.98.0-alpine-dev, 3.98.0-alpine3.24-dev

Index digest:

sha256:f29eec246365f71c4c7a4c363dff0505c5f4792a88c1cdc0cdaee1f701f5c65a

Manifest digest:

sha256:ef8cdd877ff363ea5ed705cc6339b349780af90fc77ef22c1300370f8a5d9d49

Size

63.58 MB

Last pushed

1 day ago

Vulnerabilities

0
1
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trufflehog:3-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trufflehog:3-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trufflehog@sha256:89fd9bea7f05da2eb4a30a48d121e20f139c6c77ab4b336db6d6044cfc00d28d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trufflehog@sha256:bdd3c59e55e715752531ebf5ed1d638231756ea5813b2857996f48609fe382d4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trufflehog@sha256:edc2708d4aa58582eaadb2b12acecfbab92e2082c11b9eeec005fc0c13a0466e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trufflehog@sha256:bdf06246fc0565ab67473370877173d8829767396de5502775d5d521bf2382f3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trufflehog@sha256:96da07488ea0335f10bf8e5a178e46b35ed8cffb433bd5472737230c6281bed0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trufflehog@sha256:52044def43f3b81864da4bf1d62bc49546c631f1ea6774b82c6c35ec212760cc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trufflehog@sha256:38419cdb72fd54dd9c2cb3bdebaf76fadcbaf955190c35530dd71582789e500e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trufflehog@sha256:b31f090a952e4d4dbee324b862435bc87ad543f5eeb6ba6fccc9a2d07a3a88b5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trufflehog@sha256:c3d507873ad73aed1307bea107539cf37d05e8ded1ad7a5cc00517f7450f233b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trufflehog@sha256:1a74336712a8416ec600749f0db3ff47e50345b422b4c35303b227de05ab7062
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trufflehog@sha256:079b2ded1ab96a41026ea5e5353dfee513651866f0edd2ff5a1546378a41dce6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trufflehog@sha256:657423a2559316e8913e84dbc2978b91a5afe4e6621ff0c9113088e3960aa969
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trufflehog@sha256:e33859bb13caadf761522858f0d81144fa27ce58b58e358790db98dda8a21832
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trufflehog@sha256:74725530605d9c25f6ae1ee1ecdf31e800e346d6d0049eefc22057af0ad60f3c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trufflehog@sha256:e6c3da1dbcdec6623f358dfc03be7a6b54f62aba682d47a37325f5f235911a50