Sign inSign up
TruffleHog

dhi.io/trufflehog

TruffleHog 3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.97-debian-fips, 3.97-debian13-fips, 3.97-fips, 3.97.5-debian-fips, 3.97.5-debian13-fips, 3.97.5-fips

Index digest:

sha256:809372a5f06fbb3e90b0ba33431eb12d70cfc0e78a4e4495ce2fda87de0c075f

Manifest digest:

sha256:e209d87fa1c5b90b6a1f660b5290e07280d635dde4acc398609789bf6cfa2b1a

Size

40.99 MB

Last pushed

5 hours ago

Vulnerabilities

0
2
1
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trufflehog:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trufflehog:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trufflehog@sha256:ad394b2f2ebf25d9b795d2a70596b69d4d18433541f9c4219945c74287a14509
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trufflehog@sha256:03f7b5abea1fa4d2526a7a1fc70d94fc2556393c6b39bb35c721dd4e0f72cef1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/trufflehog@sha256:b31cc6a0e66b2bf7c6fcb20a2e0ec752c5a72a8365581fe455cbcffd4bd8932b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trufflehog@sha256:dd2df902f3d1507f43385d526b6781e5a2b82389abcc9444709a0f2ef530ed24
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/trufflehog@sha256:76c40e8d1b30a63c015699d450ef7998c67a5b5f9abcde9393d775def660dcce
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trufflehog@sha256:894b4f964cebc629a47b7357f1d729c0c3d9c16af14e152ef694c93715299953
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trufflehog@sha256:2167106881329a2696796736cf96032f4041ea007d195439334999be37b28c32
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trufflehog@sha256:7c4a996a91c1e84f0c8b9c4df134d19c182a9c4f5ea027880a20194693ed6480
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trufflehog@sha256:af1ffb02b06ac6557f5198c646909a74775d5d17a824ab6f41774af14b31ed74
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trufflehog@sha256:d421a065adfb7cd1024eb4001403eb7ce8c6c1b4b84b3b49e937f1f30801cef5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trufflehog@sha256:72b61e4cc141a0a5a8fc38d542d28cb63ed5ca7b27f65b830c78573f839a70c9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trufflehog@sha256:f7e1bd34f5d7069786ea7fe17e8dcbe0554ed131d408acda5c2c9de7eadb04af
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trufflehog@sha256:12efa1e1f528a4316adfd11d37062b615ba93d8a0c2ca95b1cbbc5b45fa8eabf
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trufflehog@sha256:1c9807412ce9ae64f45096761007d36976535b778785b1893eb7f07bc50c74c1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trufflehog@sha256:64284cd72bccf05d3c3f970560eb817f41bc3ce73213a5d9275ddee2db81b234
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trufflehog@sha256:5616604eb97ac470bfafae901fee6a1650c182dda7e7f42f868ea6ad8d743974
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trufflehog@sha256:999d27a09351e8d7301cb4d139aabb114e957e54d447a97544b80c09ed51d133