Sign inSign up
TruffleHog

dhi.io/trufflehog

TruffleHog 3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.97-debian-fips-dev, 3.97-debian13-fips-dev, 3.97-fips-dev, 3.97.5-debian-fips-dev, 3.97.5-debian13-fips-dev, 3.97.5-fips-dev

Index digest:

sha256:194a264d8238810c6f92a3efe801400499a0d0ee64c02e2d9f8e9599689c40d6

Manifest digest:

sha256:58e76b8147c27554370ac1333d10299f6e4490728f3da9281008ba119bafb1f4

Size

88.12 MB

Last pushed

9 hours ago

Vulnerabilities

0
2
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trufflehog:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trufflehog:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trufflehog@sha256:3d6ba7c1869e4929f54faa62460fe49d2e7e43293437874a9f573935e150b979
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trufflehog@sha256:5b925ac636ee5c9bfaf60cb5c28da154c0770059d8fc1e0ef0f320522e7cc71d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/trufflehog@sha256:58bcbd6e2447ed2ba5996aa8f6d08fd0ca915f4debbb3b37cccc8d5fe4279964
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trufflehog@sha256:c8883040e7af7251b944d9f334ee8e821021daecde7797789845ad6ac395404d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/trufflehog@sha256:231810fa5dfb02f92bacdf0192b1e6c375ccd4eaded7145334f229cbb3211643
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trufflehog@sha256:bb2a613c129cd7d3eef740da700009ad7e78b4422d70731858ec2947371f1d8b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trufflehog@sha256:be322cafea25af61cc097dbd8202983cf5562a7f0533c197e4a5810186c62817
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trufflehog@sha256:d6d61e39005ce9d52a018e917f50e0fedb7a42b59582c2d100bf542f53a42acf
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trufflehog@sha256:b65db0dc5c66c2c5437a498c4c1bec06352a8bae707b400e8c9660e9039f9b05
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trufflehog@sha256:ce358c4fbabd91d4d5038a4bafd44977c86ee1786c8264bb2f92d003cb6aac22
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trufflehog@sha256:6de9896b6b88a17fa70de9e6d16004743caf0077a93529c5c847e42459d7cac1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trufflehog@sha256:5cf3968ca78fbf747951b331193407f52074b44f09b8ff3091b77f1f19075a92
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trufflehog@sha256:e13ab6bbb599e1e051aaf34080e8c951bfac7e65ff6de284867c8c7fd1bfd9b7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trufflehog@sha256:0dcd7421e2dd6283179e5c9d603bbcba4ab097db0f4852242c6d4d98239e2e3a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trufflehog@sha256:2e516861853a1a7137690703a320b9917bff94f34e6db54662df5d56ac57ee0e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trufflehog@sha256:8b6ae32e76e3e2b6f3b73faa986f604f51589cb3315bcaf44e895d8108a843ee
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trufflehog@sha256:e2d2e1a49044089f68657d475c5d3b5c94a7f928e498bccfece150150527598a