Sign inSign up
TruffleHog

dhi.io/trufflehog

TruffleHog 3.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.97-debian-dev, 3.97-debian13-dev, 3.97-dev, 3.97.5-debian-dev, 3.97.5-debian13-dev, 3.97.5-dev

Index digest:

sha256:dbe7944cfd2f8591fd73be80b6857b3a4ba6ef22d045afb47b54d805b1d8d238

Manifest digest:

sha256:41717a9882228d0b33f7746607223d461c3906a723c352032fa89526fc1f66a5

Size

87.36 MB

Last pushed

17 hours ago

Vulnerabilities

0
2
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trufflehog:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trufflehog:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trufflehog@sha256:c3d935d60bec5978adb3f6b4657cd086bd9fa9ee779b6c752375de14d9314ef1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trufflehog@sha256:27f497cca6d357d0df94944d7ab053e3f0b4f2d1197648b4ae24b4cffcdf0bee
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trufflehog@sha256:9e97e905fbc5dd907168f1ce73f7177b067b5472424f9331269990bfa43b63fd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trufflehog@sha256:bd7d4e0b77c860a5d4c4d612e7f446ab45915249e170049474d063cb20093069
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trufflehog@sha256:1d1f1a9eb95793d580cfdae0c891a6beffbeac2ea9fc67dd1362d6032b226ed9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trufflehog@sha256:ab1872d3690707e9eefb6ea5d00e12b7586ec5e829c60dfb5ded96d5efec2a96
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trufflehog@sha256:7b6ae5efa0ff215426d124945878d338e0909823fd36fb4199b4b03db150831e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trufflehog@sha256:fb4e8728bfdb337a7c518201da529d0ca165ae55cae5140cc720451fb26cf21f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trufflehog@sha256:4fa2e379c875ebf3f973f0a2c6dd6c3cf046195ce4ba007f7e6fd55dade9f130
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trufflehog@sha256:d6d9a59e9e15f6a13582aec5af796bd021d7dd52a318fd4d6b7e67c12fe8771a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trufflehog@sha256:72ea7f06abac8cf37a6d4be8ced47955dd1bd73c093cf06cbf44d2a8782fc8fd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trufflehog@sha256:0dae5bf61e0d337b95861f34cc0621896f2a05456457e9ce040f07aa290c1ea2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trufflehog@sha256:0e1eac070a2e5f7241d3fa1f31f63f3796c139f2d9a183f02b3a531efda2110c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trufflehog@sha256:04cfb2086ee42722b2503ac8036067ed8b2ac6f539adb12bab4eb655f1ed27c2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trufflehog@sha256:6e14262adf8014f0920ae1f37c9ffe5d12a42fc3347094f2da337b358cbea8cf