Sign inSign up
TruffleHog

dhi.io/trufflehog

TruffleHog 3.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.97-debian-dev, 3.97-debian13-dev, 3.97-dev, 3.97.9-debian-dev, 3.97.9-debian13-dev, 3.97.9-dev

Index digest:

sha256:95138d1bb8e0ded143cbbc4302ac9301d96889efb2691e280781a044aa5120ef

Manifest digest:

sha256:3cefea95c5a01a013a7859cbc3387fdfb939a534b05e7f92d6ba696e4ee86444

Size

87.79 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trufflehog:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trufflehog:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trufflehog@sha256:e2ab2ea02f44561134005a8ce9a66a3af1faca24a0f3601d013fb9e33d61b46a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trufflehog@sha256:ab98094822a60dccb7b8f21d01521e45f295b54d9cfaada146c642f9d91853c8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trufflehog@sha256:8ba299b41b62aaf851673236bfd673686936afeb3be567550031be793ea36a10
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trufflehog@sha256:bf921ae032dfbd81a998ab8263671da035b9a04ecfd3d4f67d1f40e4df54a23e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trufflehog@sha256:763d1a05fe045fae55bb5638cf15ce7c5cc300d67c3be335d229361bb00d6c0d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trufflehog@sha256:865f95a34050c1ac96c6e622b5d09c12f7db7086e4be595811b5baba3b59bb51
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trufflehog@sha256:4063f9b2703f3f430042a3a909ab72000b77f2e288499d968172304012412979
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trufflehog@sha256:d4ec6f573a16dec3209a567332e06340d752be72bc791fbab0a211088fba6465
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trufflehog@sha256:280ca476c59aa933bd74bd32b68c41259b570ca7703717f666f08758865e4005
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trufflehog@sha256:1924e938b072fa1e067d64504dbf644cd9c58f0022814de8f80f30849c508aec
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trufflehog@sha256:68071c07b95896cb06424e7d95c120975c74de42c8fbedf510653814cd898f54
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trufflehog@sha256:4d289fe9e4b29ee8812dfeefdd27bbd387effa3057425374412789ccc772cfec
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trufflehog@sha256:9382728ab80c4d383926269df532b5d5ac2d08e49e197a0d0bb78f0b77193152
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trufflehog@sha256:16246f46c0c2bfe95a0cc3688c4206fe000c45b1ffaf3c2e7fc9ba6e5b7d972a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trufflehog@sha256:ac9f4339c2d65d59717834ddb5bc3b3f6a25301f198cbafd2338d8b523090fa0