dhi.io/trufflehog
3, 3-debian, 3-debian13, 3.97, 3.97-debian, 3.97-debian13, 3.97.9, 3.97.9-debian, 3.97.9-debian13
sha256:d1c1bba7d849262786ad0c8dd5feaae7a98635fd75d81b453b3a32530cf6d916
Manifest digest:sha256:e45ab2ef6805b54d881442e7d8a84f63052eb5be70eb5300eae13abbb135b25b
Size
33.04 MB
Last pushed
7 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/trufflehog:32. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/trufflehog:3 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/trufflehog@sha256:9866bdb1ac999af3273867411ba08c59d42f6a70d5fb56f2dc8d92f30b01ac32 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/trufflehog@sha256:49687b9905fa662506533b915a9d49da7d3f6850d9ccf33cd6cb338207f6c762 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/trufflehog@sha256:689defabc9802843de73bb0d92f17c21afa45cf36b9c56d1388fbb3aba9bf42a |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/trufflehog@sha256:c96bf1b0b6b922f1ace2ecc352a05c9acbde11a5d5033a6123f3f6f54d5af794 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/trufflehog@sha256:07e6683193340ce1b2edc2a77da3ed6d7056fc506d076bf0d52e015f03be371b |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/trufflehog@sha256:9578a3766ae0387ae7885810308dd9763f8e5f9955a54c060ce4fef53f588999 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/trufflehog@sha256:31f511f361bc4f91ca656f19e115f6d071947ec0b9ce9a580f0a557b272ce73d |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/trufflehog@sha256:397aedb671d50fb92083ad82de44078e95bb02bd3c26203571415399abffa3a3 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/trufflehog@sha256:5d7ac5624ee146974812fab4fbb2d6e89a1dedee4115e38b4570ab59760b6188 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/trufflehog@sha256:a2f06c04a9f2c51a5aa7f7f97d2a14cc98a31d5fd504d59318f73e4adcbbd41e |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/trufflehog@sha256:67405b450a32fad5ada9f39cfc30b1c452eb44be88eaa0f2df4e1666a6eee9e9 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/trufflehog@sha256:75ff7329c22186337e0cdee76edff21c3248d477b0c12bfd7e76823231001e52 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/trufflehog@sha256:3cf283b11f097f44b91d760aff284f0233960c5fcdb6a27f46eb9206e49ee144 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/trufflehog@sha256:9f06fcdc9363615f7c3e6650832bed121853f502eb12677293ab9273ded6a173 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/trufflehog@sha256:a7d7b0adf532b1ebb37b555ee74ec268f87f1dd23665e0c479183aa2d2d9570c |