Sign inSign up
TruffleHog

dhi.io/trufflehog

TruffleHog 3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.97-debian-fips-dev, 3.97-debian13-fips-dev, 3.97-fips-dev, 3.97.6-debian-fips-dev, 3.97.6-debian13-fips-dev, 3.97.6-fips-dev

Index digest:

sha256:8dd44a1ed9f8009987907f036fdb3dc9291cccc2adfa69af78d070f83a8d109c

Manifest digest:

sha256:d028c5bca12373a48ffacbd6b83f84e97151ad63f0409603778af68642284c33

Size

88.24 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trufflehog:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trufflehog:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trufflehog@sha256:95c98b885a55a3045665fb388cb28188254c9c67d0b49778e9971103ca28901d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trufflehog@sha256:67bb94bc64fe918852ea0eabc9e1204aa7e110acb6c1437cfee63a5d8d4a27ca
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/trufflehog@sha256:1247b0c5d6f4094730c91781ee76a7a42a984d48df2d5fa068c53e31b02c59be
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trufflehog@sha256:a498b800a39f335804e74e0561bac26bc3d69fb540fe25ff95e82f20b0d7a69a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/trufflehog@sha256:36e3a8ad4725e87e1694fc3ae7f1fa80bff0d82322ba56c792f613fd90246b2e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trufflehog@sha256:f967a7b6262ec47a92468d3db974e41050dc0e81f12e5b24d6de144a86b98c4e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trufflehog@sha256:cd8b30e6c9d6983ddda41642dfb0742da0bd9c687aa04d43447070d713142e12
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trufflehog@sha256:3554b3562772939a437e2a345e23025f3d301f4dbbec11441a41ab23c5df3e2c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trufflehog@sha256:a1f0efe22f165fb3d4fc7905951844673f23a58d5ca121fc60758bb79ce65537
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trufflehog@sha256:067c8048ddcb5cf6490467071848872a02ea0ad251f025bb8f5ac09c845e0987
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trufflehog@sha256:f96ddfd115d4a66398ba6164e04b891f30b2484b75b3a0a3a87a5b30cc5d6744
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trufflehog@sha256:78319434f312c655ab64a2785fd211a7b043d304ff40bd6d8f96e3a5cdad16c3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trufflehog@sha256:6e3e50a71d52aa34fd8d6de4c8c7888918e894e9a57b3411a7a5e3a34a958efa
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trufflehog@sha256:256f48981a69e3fe774a44b4f84f0788ea367d702b53c735bc03fa2719f98d6b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trufflehog@sha256:1e40906cf489e7e84e0cd1f5b05fb5055d82f74a2c7bf92a0104af46bffcabc2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trufflehog@sha256:7ae3ea48a7e125d4969920635b236a4a023a442953bb83869c72c756bcf54881
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trufflehog@sha256:70579d07d2200f7de4e2b62aaa4312eb00ba621efe0b5375004bcce256f277ab