Sign inSign up
TruffleHog

dhi.io/trufflehog

TruffleHog 3.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.97, 3.97-debian, 3.97-debian13, 3.97.9, 3.97.9-debian, 3.97.9-debian13

Index digest:

sha256:d1c1bba7d849262786ad0c8dd5feaae7a98635fd75d81b453b3a32530cf6d916

Manifest digest:

sha256:e45ab2ef6805b54d881442e7d8a84f63052eb5be70eb5300eae13abbb135b25b

Size

33.04 MB

Last pushed

7 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trufflehog:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trufflehog:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trufflehog@sha256:9866bdb1ac999af3273867411ba08c59d42f6a70d5fb56f2dc8d92f30b01ac32
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trufflehog@sha256:49687b9905fa662506533b915a9d49da7d3f6850d9ccf33cd6cb338207f6c762
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trufflehog@sha256:689defabc9802843de73bb0d92f17c21afa45cf36b9c56d1388fbb3aba9bf42a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trufflehog@sha256:c96bf1b0b6b922f1ace2ecc352a05c9acbde11a5d5033a6123f3f6f54d5af794
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trufflehog@sha256:07e6683193340ce1b2edc2a77da3ed6d7056fc506d076bf0d52e015f03be371b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trufflehog@sha256:9578a3766ae0387ae7885810308dd9763f8e5f9955a54c060ce4fef53f588999
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trufflehog@sha256:31f511f361bc4f91ca656f19e115f6d071947ec0b9ce9a580f0a557b272ce73d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trufflehog@sha256:397aedb671d50fb92083ad82de44078e95bb02bd3c26203571415399abffa3a3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trufflehog@sha256:5d7ac5624ee146974812fab4fbb2d6e89a1dedee4115e38b4570ab59760b6188
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trufflehog@sha256:a2f06c04a9f2c51a5aa7f7f97d2a14cc98a31d5fd504d59318f73e4adcbbd41e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trufflehog@sha256:67405b450a32fad5ada9f39cfc30b1c452eb44be88eaa0f2df4e1666a6eee9e9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trufflehog@sha256:75ff7329c22186337e0cdee76edff21c3248d477b0c12bfd7e76823231001e52
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trufflehog@sha256:3cf283b11f097f44b91d760aff284f0233960c5fcdb6a27f46eb9206e49ee144
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trufflehog@sha256:9f06fcdc9363615f7c3e6650832bed121853f502eb12677293ab9273ded6a173
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trufflehog@sha256:a7d7b0adf532b1ebb37b555ee74ec268f87f1dd23665e0c479183aa2d2d9570c