Sign inSign up
TruffleHog

dhi.io/trufflehog

TruffleHog 3.x

CIS
linux/amd64
alpine 3.23
Tags:

3-alpine3.23, 3.97-alpine3.23, 3.97.4-alpine3.23

Index digest:

sha256:51ae674526f271fa154435b60e6accb6b420c7ba33a69e32139396b458ef2ae9

Manifest digest:

sha256:10c6bc70dd1428996bd9bb956a98943ba3cb8f2eb24d5a674ae237bc5952b37a

Size

32.18 MB

Last pushed

11 hours ago

Vulnerabilities

0
3
1
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trufflehog:3-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trufflehog:3-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trufflehog@sha256:46abd2c75af008348db0003311fe330b8beee7e44a08e4dadba1c46d36a848f0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trufflehog@sha256:9b1acbbb04e5135c631924b9d2241822c7b969244e4c4945a0937d87ae5bb7d9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trufflehog@sha256:6a504be5fab11acdc0165423ed0bdc45b74d1f9b460d5b1c52c20591d6ad6ce4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trufflehog@sha256:6c98ee1d167f7a5b0d21e6da58b49a69b6dab2239df5e3573b9f0f2fcc9912ef
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trufflehog@sha256:66fd3cf5f928fd146b86985605e611fefc6346db24e9c5b23c81cc71feb8d4f8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trufflehog@sha256:8c43977daa6fd6a59ee24b5c9d0eaf6c229d35a0a6c5f1dfc63d63ace204a0ec
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trufflehog@sha256:14c3a86441cdcc0d3aa637a19d6c8c5d865a993d506f769a65e0652b3f8a048b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trufflehog@sha256:91ca5649d8a8daf79e3f26e0dc6c16cbf1cf6e8467af21ccaedf9be2771631c2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trufflehog@sha256:cfc2b2a0561e0a393fbf65303d16889a5b662bc403736c92bb546ece4bfc74ee
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trufflehog@sha256:005087ff8d720e328f1fafcdbb59d6b5ab36929a22fb317522559fd1ffe89347
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trufflehog@sha256:1a6cdebdc948601d8ee27dcd40be005e36f2f2623507aef42cdebc1d1aba2e34
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trufflehog@sha256:f295aea88d90ae5149f6012768c34f7d4865cd3da7d0eb69532d8178430899ad
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trufflehog@sha256:6af3ee59707ca625708c5e91d48b2fa47bd4a987f015488064773b3d70da994c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trufflehog@sha256:42560a11d9430d23010b83cc6f321e2806f6160f99e3ab8bd5a7493d55baccdc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trufflehog@sha256:88a1b49786a6e665beb009477525a1e907c48dc8ce9e14c57aa3322df1477466