Sign inSign up
TruffleHog

dhi.io/trufflehog

TruffleHog 3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

3-alpine-fips-dev, 3-alpine3.24-fips-dev, 3.97-alpine-fips-dev, 3.97-alpine3.24-fips-dev, 3.97.5-alpine-fips-dev, 3.97.5-alpine3.24-fips-dev

Index digest:

sha256:51e4a6acb090edd13e0c49c06ebd031ae87c8bcd0552729ee6c03b20410e70ed

Manifest digest:

sha256:8a49f22627f19b60be09600938e067f699f57a41a75835546dfd56089d4f523a

Size

68.76 MB

Last pushed

4 hours ago

Vulnerabilities

0
2
1
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trufflehog:3-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trufflehog:3-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trufflehog@sha256:07c40f1985bcce151252016ce2fcb84d3942ede4d5eb4733a48133c59f0d8ba4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trufflehog@sha256:f91bc08a51361c573186a83838357777749a469117cc1cd8bd6320171c018613
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/trufflehog@sha256:f09591e2843df578c122e18a17b552be29595eaaab8cc5b51b63202f68ebf3dd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trufflehog@sha256:71d871b5ef2b5ea056662986c4315556164d67706e84d7cdc7f4cc7b137b3513
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/trufflehog@sha256:1a1f8ba9b4085a00aaccc87a983a60145c6c7b9a28c98c7b1e2718293477ac06
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trufflehog@sha256:7449fddf70335a641af9f6d5864af74700372d36dbca3b4dac60172a65cf29a1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trufflehog@sha256:77d5d9ea0799911b9cadf7f68c0fde104f2750e463f885dca1e9413a749c707d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trufflehog@sha256:5569e616fc430363a9cc06ca433c1a43012ef9bc5ce9b2dba3999e0d9deaa320
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trufflehog@sha256:551dc6821e6cd810bfc675b98f7bc04b16a3a41b32e8e4883ebf99b86b8abdd1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trufflehog@sha256:50f853076327e1fc6e892569689db8f3af0ed5a99f7a9720a2564130e1c024c1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trufflehog@sha256:ca31d87c2cbc0962bf948b9ac122819d2ddc2008435cb45bfd536c344e67e988
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trufflehog@sha256:774b3d0a7ef36cd9ab674212d273fbb5ad444eff4ffdc32434a43c5470cbc7ff
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trufflehog@sha256:ac31c655376addf997c56a02cf73fb6f0fffe1ff3b6740cab81f9205c319fa8e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trufflehog@sha256:ae15ba4388b06e8d1e78efee8576eb00882650987269b844be51cee0faa33bed
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trufflehog@sha256:0d63e4db735bd785b5e4e1c689791784aaa12fa9e5612dedcc1c5cb9d884df79
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trufflehog@sha256:4cb80e01d8607504daca644a590afaf323d217a0d94ccec94e47da28d2741415
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trufflehog@sha256:8dab09ec65f517ce670853f06db16c64952452d45c9e735102a0605602f9175e