Sign inSign up
TruffleHog

dhi.io/trufflehog

TruffleHog 3.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

3-alpine-dev, 3-alpine3.24-dev, 3.97-alpine-dev, 3.97-alpine3.24-dev, 3.97.9-alpine-dev, 3.97.9-alpine3.24-dev

Index digest:

sha256:552024d4c65c8775d53e835e1a6927c38e73eac83c6364b3d4304c7fc497348e

Manifest digest:

sha256:f5a9d115c6d6987a547efa9bcc8dc484a78bf87e8a7f5b514dc3eb8cba9dacbe

Size

68.42 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trufflehog:3-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trufflehog:3-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trufflehog@sha256:590f321a74c2fcaa380ba6f80320cfac17761eccc5cb5e975aa597e9667ff5fc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trufflehog@sha256:54b5f70672bb4386c391837eeb5d3ef66bda0f1d1ea3b2b698989608b817de28
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trufflehog@sha256:afa8b092cd74bb73c99d8166691f9b9474c5930b3ee1a4e2c850a679337c1d53
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trufflehog@sha256:df86cf3003f3e41e3e6346ef62c985f034c694a2301d8a662c641ddb3e2cf4e1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trufflehog@sha256:5d75ca3b071c63a365310cf62a620cbd67c0dee4563b0eed8d6d0a046170a6ac
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trufflehog@sha256:ccab29c39947d9b7fc9394470982c92c4195e8410baff2eea8d7fc61b456aad0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trufflehog@sha256:3d0b340f8cf10ad2df4634ac4d6345de7222da48adbbb4c5bdd858bb7204473d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trufflehog@sha256:95405ce17efa2cb62abbfa0b6f00131a2ce4ea4a69099dbb52e70c743211ce92
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trufflehog@sha256:3f740dda4e8425b0eca4f59840451602176f80b203d673cdfad60ae3a3f7142d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trufflehog@sha256:0934c257e8fe92003fb2d0f1944a31eecb06fd418220b36d40d02f618768edef
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trufflehog@sha256:50d3c873a3a5e55db2ffcd302fb0025409f1b1b5db916bcf910a14eca3562dce
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trufflehog@sha256:0774f76aa670e27dac3b4b4f729fc35846b1933413382ace89a3795b3a7b350f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trufflehog@sha256:d234a05262de197a3c9772a09dcf0a568c3c6ee46209c2c2f8499ca397b62b26
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trufflehog@sha256:9eb22d576d0bfe0b0ae3040b6575f030b7807d78218cb49b0ef363a0df954da8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trufflehog@sha256:515ba757d86efc3b4ea1872e1c914ed831bc9107255ca00b9d21a5d942b1d04f