Sign inSign up
TruffleHog

dhi.io/trufflehog

TruffleHog 3.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

3-alpine-fips, 3-alpine3.24-fips, 3.97-alpine-fips, 3.97-alpine3.24-fips, 3.97.4-alpine-fips, 3.97.4-alpine3.24-fips

Index digest:

sha256:ac64fa2ec6ccb0bd0186c402de67e0d628d6d04bdf0c7d84abe8f329eefc7a4d

Manifest digest:

sha256:26125b6914cf1c0ebecf6c91f06181fc521cf2624c2313f49c43802333f548a1

Size

35.62 MB

Last pushed

7 hours ago

Vulnerabilities

0
3
1
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trufflehog:3-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trufflehog:3-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trufflehog@sha256:3f043e14f649ad6d36c382ffc5c8f0a62a2d16eef93844eab4f5637b641fd1b5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trufflehog@sha256:def0e4dac9ae5700fe2c83608eeb0a9337b739fdb2ece9dfb5fb939ff4188240
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/trufflehog@sha256:979eca5e4eaade50f33c4d9a257aaf27a0cb98559a055d0ac80ea9a764f26e85
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trufflehog@sha256:acd0ee6168d8f74b6befd1da4539eb51cc67e9cf5c6a50c644b8d3ba0cad1ed3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/trufflehog@sha256:51a1f159ed33213a40ea43ce26c08a12b1566f068135ca1be944d3a5d572469a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trufflehog@sha256:1bff168557122ca33e77b1562b1dbfec14be4dd5933d66e7e0ee2fbcf9d8265b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trufflehog@sha256:809ac01f1fe8c2694a1036ae6fbd2db525a0e3b704e3381ae0f84dd6a541e2dd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trufflehog@sha256:a7c5804311babe6916bdfcbb610023246032cf40d701512503e65665dc148803
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trufflehog@sha256:c1c0cda8722a5f4eda9c5925dd91e0f56dac8d7eaade72fb367338c868cb7e61
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trufflehog@sha256:28e768f5e4bb4a0042ef4cdd7a5b69971da6443d1ea08e8cc75664c9aa98d22c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trufflehog@sha256:f40e9e66a5894ab053f6112edb55b793a94caa96bd3395cfcd452ff92a5ed341
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trufflehog@sha256:68c23b69f2bde8469fd8fcd2f8f81bba6c9fc7206ba4cec26d5c41400630f613
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trufflehog@sha256:7585dce61b093d3b14fe3b75ad4a8852ac41cc29d5cc4bd99e3db4abce3ca7a5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trufflehog@sha256:84b5582e66ba1ad1838898486641e59f127b64a2f68fc3b34d09a77756558c0e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trufflehog@sha256:02d1acb1bf01a219668a36657e8c946e02599551a88fbd00e20f5c0ce231b064
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trufflehog@sha256:3c7713b7090e4049d3607ce22c4b61a52295642211a22a7c00bc7c01b39675ef
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trufflehog@sha256:30fa197f47206a31b8f4cb5bc19f9cd7fc34ef07003b33490c90b17f2a871c4b