Sign inSign up
TruffleHog

dhi.io/trufflehog

TruffleHog 3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.97-debian-fips-dev, 3.97-debian13-fips-dev, 3.97-fips-dev, 3.97.4-debian-fips-dev, 3.97.4-debian13-fips-dev, 3.97.4-fips-dev

Index digest:

sha256:672a56cff515ae4b5c76170f955d7377129edcf8a072c2109ede8cb32f591db5

Manifest digest:

sha256:96dbaede3e2a4641342868df401987f21a9d3b489904f5dbb89f419dddd8ba03

Size

86.26 MB

Last pushed

2 hours ago

Vulnerabilities

0
3
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trufflehog:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trufflehog:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trufflehog@sha256:c84ab346924daa749e367a75487021fda2df9050ef2e1df0075b4e78a6dd1210
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trufflehog@sha256:91f609d7605f8d4d8b9d98e7f58cf5d56bda83e9d4c65dde6882065764256f70
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/trufflehog@sha256:acbde8bcfc39562d8dab4188c51baac8682f983bc63904d3c168f9a319836359
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trufflehog@sha256:9316043d32a6d9eaeb8101e848035df75784156138b4e8a482c41425ca4ffbbe
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/trufflehog@sha256:636e34009a64973fd20607f2f488c00afb88aa98c6d4482e1db1dc467f3d7397
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trufflehog@sha256:006429808e1e53e3b2eddf44ec56945197c35946ef4f679479c2272f2fb54791
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trufflehog@sha256:c17791ee49145f91b761a23071355cdae85498e4dd528b9c73820b56ff8c9007
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trufflehog@sha256:0942d020a23fa9858661b4242106a66fa36021949fb5c0033e404e03801f6ebf
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trufflehog@sha256:39b84fd91654c4790350e1e3c2bf68be2daad821b0f57842b2b0fc692f7a9193
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trufflehog@sha256:861024c377531d058588c38b4c37646d278d29d4935eb903ab7afe3578f9e68a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trufflehog@sha256:39fa3c171136c6754ab9cb3c1e24ef34dedfc9884d218e0587551129d811782d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trufflehog@sha256:e3cb5cfa195d995abee0134f2b0a5a30e79db332a13952941d8bbf8d362784b4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trufflehog@sha256:dd396d4bee85cf762697593844846bd5c956ee8a392a480bcc6a1bc70aa06af6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trufflehog@sha256:a34f78702d6fea77b31d0af0362ff2e336ccf439723e0be8ebf82aed91f5eaab
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trufflehog@sha256:1bdc56d9d7a01955e9ad5dd4bb01d659d5e06c160c5deecf5f1a8031a09fbd4c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trufflehog@sha256:056ca3cd83316e3b54ef8378dcad9d5c60e8b87076e7eec93abe82f93c8f182b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trufflehog@sha256:9c039b4dab3184f8cda2bf14bb6b07128db14ddb701c7b99bc43fe605025ebe1