Sign inSign up
TruffleHog

dhi.io/trufflehog

TruffleHog 3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.99-debian-fips-dev, 3.99-debian13-fips-dev, 3.99-fips-dev, 3.99.0-debian-fips-dev, 3.99.0-debian13-fips-dev, 3.99.0-fips-dev

Index digest:

sha256:d128cd3d7f024de00a839e2963e7323e96d04c7fe1b54328f3a801066ac06e23

Manifest digest:

sha256:8dd92cbe945d611a70d0a90204fcbe12b3f2c142b5cbd6ec37b1894b754f0dd9

Size

88.64 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
1
1
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trufflehog:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trufflehog:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trufflehog@sha256:3754be6584102acc192e830f64e1679fcfaa0cd6fcecf177253da2b757ddbc6e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trufflehog@sha256:67d6e22072235f7a3db85644cf0f7b7fc24422b5e9d19506913d75346ea54108
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/trufflehog@sha256:fbe1a39b72a5500486735751a3d3ab2ea9df14a861f1745caef879eb6135352c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trufflehog@sha256:ee05217d16d7b2eef1226e8f6e0cfe4a2257dff52eaf5a6a5d1b7462181c3aa8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/trufflehog@sha256:646ecd937d2b90fa66ca6ebe15e98d7b05488f3cefda1e62ba3423cbf17191de
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trufflehog@sha256:e30b5697741fc6859e2d52f078d773f169423f0b24a456dc10a1252d7a988fbb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trufflehog@sha256:73fc4c4b4e1b4711c9db4d3dfb0a16080601c24398b7e33fcdc857ac3c3e4146
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trufflehog@sha256:f93fa3191c97c37f3fbd4330dbee7da1f06f78d0933e965a287bef8ac912597c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trufflehog@sha256:1bd5e55ad5889db41269ef6191e0a42ee54b9bebedf9b1dd70acb12af74e6e2d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trufflehog@sha256:469a8181736cfde50ed1d0014c4ef19b5a57ed22d95f71bb73829bf0b95a429c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trufflehog@sha256:6972b3ee0ad5cd8973143a2ad0db8eef36f2a794c23e7df199cb3b41f3bc24bc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trufflehog@sha256:df0971f173e85a2935a7e9a0d520f616b2bd520af724ce9c0e0ee28cc7657bbc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trufflehog@sha256:7745a23eb344dcb25c9faf81f4f9b4361a8c915f11277c3c526a97f7dd6ebdbe
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trufflehog@sha256:9d1e2d883850b54a54b42176014fe79d31daaba378d7be29b5ffb4bff53456e0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trufflehog@sha256:61bca9513545a4e3bf155d4bb42776b5e41aef9651020fa6b84ad8cc5e6452bc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trufflehog@sha256:e6310a89556ba62c6fe039660e8e28b40fe60663d15800d12c3003efef49fdd0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trufflehog@sha256:6c1825dd6c7400f15e74ab443e573776040d48edbff3d7555b7dc68bec193a49