Sign inSign up
TruffleHog

dhi.io/trufflehog

TruffleHog 3.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

3-alpine-dev, 3-alpine3.24-dev, 3.97-alpine-dev, 3.97-alpine3.24-dev, 3.97.4-alpine-dev, 3.97.4-alpine3.24-dev

Index digest:

sha256:b1a50ec0b3000b5dc2a15210cfca038cdba124bf975f8668323463d527dbf8b8

Manifest digest:

sha256:5fb0d527753310496d9c6967ee198b07d76248ecbf960f263df8884a29eae01d

Size

66.06 MB

Last pushed

8 hours ago

Vulnerabilities

0
3
1
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trufflehog:3-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trufflehog:3-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trufflehog@sha256:65d469fbe3a5e348493875aee9cf467e3b81d99eafc4193b015573b839624e5a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trufflehog@sha256:df2b2324f3f5ff79f2020777819ba03f6b28147050cd8e594a4f3bdb0d217e14
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trufflehog@sha256:fb984b14f988e12cff223677b6885a80a1acf7880dafcdcf7e6bf2d94c1111b6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trufflehog@sha256:1e34e21022565d9c7ccbd0af8f35652f836ca90b0f1a7eb3213022f1163926c8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trufflehog@sha256:796fb34facd617d29835edd003de29799fe18a0941f8c848e675d52fda6109d1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trufflehog@sha256:5962e09c8a253f6d11114465edf1b8722a81be998c9cf44395d6e08568badf9e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trufflehog@sha256:9fbef6d8bdac66f6f835c399fab309e0037501b9e90d0817021f3bbdb571f114
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trufflehog@sha256:8c6f4e2b793f01697d3e5b39cdab1625a31aadf6d3bc68766b6dc94598a99cc2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trufflehog@sha256:d83270a19092aefc0010ac7316121480e214c9b12944e74699589e642d8d58bb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trufflehog@sha256:790d673043d15f436af4c1728492c3476b1ddb1ec4dc473d7917c2f148978e72
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trufflehog@sha256:d620d5f6726c5423da7e0aa777bb7b4f9215c4563ce0360a98865434d5427609
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trufflehog@sha256:cd3d4906ebeba64b4469facb43cc5fba42b11d0f5f6921721b899832ea8da147
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trufflehog@sha256:b644207cb8163409e9289928f0e02f5772b360a0498e540a2c59fdbab7f1dc9b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trufflehog@sha256:9a451bded530e0f0e9d2aa9785241c98ec4d7e105249a88b664c471680c6a147
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trufflehog@sha256:3424a0ccf6973590ba64821c80b1c05c21b999af14bbbb055fd2505aecd2b238