Sign inSign up
TruffleHog

dhi.io/trufflehog

TruffleHog 3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.99-debian-fips-dev, 3.99-debian13-fips-dev, 3.99-fips-dev, 3.99.2-debian-fips-dev, 3.99.2-debian13-fips-dev, 3.99.2-fips-dev

Index digest:

sha256:1737cf8309416446820589b43e534f7d7898adf952ca142c1d91b73433a4fffc

Manifest digest:

sha256:7468b6e70ba4a39663d1d90a85e68aca28b2f5a4c2cc49b1f027459e5492b065

Size

88.66 MB

Last pushed

11 hours ago

Vulnerabilities

2
8
1
1
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trufflehog:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trufflehog:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trufflehog@sha256:27007ce59dc635b8dbf538aff7d8024336580b6ce3ae43819899e339b5f87a10
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trufflehog@sha256:8ab8619ba63bfcc9d9152289959816ffed8005e8e4cbd90f47904fff7b78f4dd
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/trufflehog@sha256:3655d7335f4d58963cfce24b22523962197373a9d1595caf5764d71ee128734f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trufflehog@sha256:97cd98d25de937b708baf4afb5402017c7dea2c8b12707ba39f9a5516d1d350d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/trufflehog@sha256:25d276b3e25110e8d0aed5a61c172a38e126b5dae15d65fd4c18423061459b8c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trufflehog@sha256:43ab204a1b2d88ac28d9f340f3f10142f529679e762fb4d1674e01b62ca59de2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trufflehog@sha256:3dba6b8bae750afd3e27d6e278f0a6dc1f555637fb8933214cb71a293eea5cf3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trufflehog@sha256:5c472113bd6dcc91dde98b21758f9bc0ba7c2e2f5a1c0e26f435db49ddfbd771
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trufflehog@sha256:0c17d92ca24e5a7b2dee10a494b0cbbebc77681a04d150e4fee7ca013487be59
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trufflehog@sha256:ca063e6f7c0f21bdf1c6045d077070a967c6ed980e7747364d0279fa180472c8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trufflehog@sha256:6539b3fbcb6d524ea969bbd96bd4f7f5e5112c13c9d53b9f3813dbc8649e66ed
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trufflehog@sha256:e9e57c9d487cd273a5e115755051cb65eadbebc3f325ff7d14f333d63ecb0727
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trufflehog@sha256:1d211818de62de389c09cb79ddd3a9e51bfb3213d5f6e3edc5938b47e0276685
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trufflehog@sha256:e252509cdea6ca300ba1c99240052c8c0fd7acaa6e90857aa28894fb71b576e2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trufflehog@sha256:8730d21ff650862e32c67e8e1783f5feef7a6562b84787d4d54ef953a1ef2362
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trufflehog@sha256:942394d2c299dca8d37edb61ea554801b07d769eefb77bbeea6be59166ec23a0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trufflehog@sha256:c25bd4f40be88d20c7e23c9849e297d7b3bfc3bae057bd3d01f7b7efb113727e