Sign inSign up
TruffleHog

dhi.io/trufflehog

TruffleHog 3.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.97-debian-dev, 3.97-debian13-dev, 3.97-dev, 3.97.6-debian-dev, 3.97.6-debian13-dev, 3.97.6-dev

Index digest:

sha256:5e6f1967b6102e01bb0582665722fade0611f7425aa772aa4fabe313e78d9a3f

Manifest digest:

sha256:5b43f69ca6d02ac601c17e67035d12e63322c226639cd4906fff467969e269b9

Size

87.47 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trufflehog:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trufflehog:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trufflehog@sha256:b030be5f924aa8f934e9c353551d48c4bfa2958db369fc8cfd7635d95d44a840
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trufflehog@sha256:a33aa5f49b2f022a99030c77412440f3eb206937c735196043e1508a4f3cd66c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trufflehog@sha256:73d2707211b80c08fc67b5d0846f8577eb57fc049b802e19fe6fe2966329c371
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trufflehog@sha256:c4e726d7198461fcdd59cf1adca6f124e0739dd44f3ff2674550b1ad12a7bde2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trufflehog@sha256:7b6530e25b85346d0e1b1963c2792b19f7c49c8f33fe0d8e45906c044ddd6728
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trufflehog@sha256:cc6384d55e5890c35af99ecd634dc701fc68b691f853bf755130d870167dc1b8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trufflehog@sha256:ec8f5e20906107c8547bba3edd07f29905d379a888accf1a6ab2a3d4b482035b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trufflehog@sha256:7326f42d25ed08b5f06d8a4c51da7562a806cf030d5f357f15365e3a106727e4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trufflehog@sha256:4abdbdcad75296ebed5a52af85b73a69fa928e26d9b2004c22f98b354c07c9fc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trufflehog@sha256:948787c956de6688158ad49343757c48e6c4c1f12a084bd990daa68dde7c3845
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trufflehog@sha256:f3de1a4387dea19d1c427c698a97c53702cd75569d5f4c8c1a7e6557ef7e8eed
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trufflehog@sha256:d9dbbf1ddb22769bd7ea004106c1a63b83a6f665cb9049e45ad2dc215c13a520
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trufflehog@sha256:258fb77c9fc4f2657265e917e72e2868941a4618097f9ea3d850bf691549341b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trufflehog@sha256:482d28fe17794c76ad13a90e23820abfefd7abb25d2460ee4d55a2e9ad5d8327
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trufflehog@sha256:32f1209d4aac712de30f596d7d4396058c01ef8c18343b60b6a5b3ff7b1b175f