dhi.io/trufflehog
3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.97-debian-fips-dev, 3.97-debian13-fips-dev, 3.97-fips-dev, 3.97.4-debian-fips-dev, 3.97.4-debian13-fips-dev, 3.97.4-fips-dev
sha256:672a56cff515ae4b5c76170f955d7377129edcf8a072c2109ede8cb32f591db5
Manifest digest:sha256:96dbaede3e2a4641342868df401987f21a9d3b489904f5dbb89f419dddd8ba03
Size
86.26 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/trufflehog:3-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/trufflehog:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/trufflehog@sha256:c84ab346924daa749e367a75487021fda2df9050ef2e1df0075b4e78a6dd1210 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/trufflehog@sha256:91f609d7605f8d4d8b9d98e7f58cf5d56bda83e9d4c65dde6882065764256f70 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/trufflehog@sha256:acbde8bcfc39562d8dab4188c51baac8682f983bc63904d3c168f9a319836359 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/trufflehog@sha256:9316043d32a6d9eaeb8101e848035df75784156138b4e8a482c41425ca4ffbbe |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/trufflehog@sha256:636e34009a64973fd20607f2f488c00afb88aa98c6d4482e1db1dc467f3d7397 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/trufflehog@sha256:006429808e1e53e3b2eddf44ec56945197c35946ef4f679479c2272f2fb54791 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/trufflehog@sha256:c17791ee49145f91b761a23071355cdae85498e4dd528b9c73820b56ff8c9007 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/trufflehog@sha256:0942d020a23fa9858661b4242106a66fa36021949fb5c0033e404e03801f6ebf |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/trufflehog@sha256:39b84fd91654c4790350e1e3c2bf68be2daad821b0f57842b2b0fc692f7a9193 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/trufflehog@sha256:861024c377531d058588c38b4c37646d278d29d4935eb903ab7afe3578f9e68a |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/trufflehog@sha256:39fa3c171136c6754ab9cb3c1e24ef34dedfc9884d218e0587551129d811782d |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/trufflehog@sha256:e3cb5cfa195d995abee0134f2b0a5a30e79db332a13952941d8bbf8d362784b4 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/trufflehog@sha256:dd396d4bee85cf762697593844846bd5c956ee8a392a480bcc6a1bc70aa06af6 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/trufflehog@sha256:a34f78702d6fea77b31d0af0362ff2e336ccf439723e0be8ebf82aed91f5eaab |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/trufflehog@sha256:1bdc56d9d7a01955e9ad5dd4bb01d659d5e06c160c5deecf5f1a8031a09fbd4c |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/trufflehog@sha256:056ca3cd83316e3b54ef8378dcad9d5c60e8b87076e7eec93abe82f93c8f182b |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/trufflehog@sha256:9c039b4dab3184f8cda2bf14bb6b07128db14ddb701c7b99bc43fe605025ebe1 |