Sign inSign up
TruffleHog

dhi.io/trufflehog

TruffleHog 3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.97-debian-fips-dev, 3.97-debian13-fips-dev, 3.97-fips-dev, 3.97.9-debian-fips-dev, 3.97.9-debian13-fips-dev, 3.97.9-fips-dev

Index digest:

sha256:28553dbe0b2c55a0fd4b6571a18c37126459d894dcb6c722c96711194c255614

Manifest digest:

sha256:41a4a6d206482bffcd436f19087f45880490f3caeeae44da2e4f7f26d2b630fa

Size

88.61 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trufflehog:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trufflehog:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trufflehog@sha256:8f13e7ac2a21e4bdb2c75dddfeda0d6da3ef1ef29af2b0ecdd1793e6b49b4d8e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trufflehog@sha256:398faef0c9a58f968342c3b52bbc5216ebe66ebb8f98e11fafa248986448073a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/trufflehog@sha256:54d3c737ba08568bc6f2e909d91ac07e48b0ee4129b3806709404038e8815779
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trufflehog@sha256:45c1cd0436e94d8f4337c80c42e1e197dd6fc46a4b17666c493d6e048fca36e5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/trufflehog@sha256:ee2d1a5c50c771a7da02c6b3b914e2fcacc65177a68acaafc83e3f23a0ff6570
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trufflehog@sha256:1de4a51c7885fc5e790ba06e300826c53875f116fbcf681ff79cfca563001f84
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trufflehog@sha256:3420ebea035dba27d689047bf9d60a324ea71451a7afd078aa7b4e1f468bed65
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trufflehog@sha256:5b639f9b03bd173b0aeaeb2629502cc090eec099ef0d20414a5eed70fae3d43f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trufflehog@sha256:98ddf9b7de95c0cd2c77352122991e5c46a815cccc144c2116ecb65d6aa423c2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trufflehog@sha256:c70985f942f847642ea1f2ae2fee87bfdf6c567a3c57e454fc4b0316528776d5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trufflehog@sha256:0c84117fe333884e6d7fbf89e74a7752c0fdd2088a85bd867e05654fb86f081e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trufflehog@sha256:4f90807f4c28f73505eda96051e219cf12b35bb72d9fe01bf8aaca29c37ccad1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trufflehog@sha256:b822ac272d62aa36c23a26199510b82ebce26fe8a5c0f0c3dd4de349c7f9e750
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trufflehog@sha256:cf7976ed6642ff59d211b171cbb3eb50d837d39140afcc524588978e875fb32c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trufflehog@sha256:34993c9fac26201340ca8844a139e80d201a4ba0446bf5a30c6abb728e12f250
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trufflehog@sha256:56b5f13faefcd943e4bb82a8133243cd8fc11ffdeb0a6e88a66892e4fddcd458
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trufflehog@sha256:df3b17ac9fee9070d83c011db68ad12a88aef6bb5574901717c5edac9852425a