Sign inSign up
TruffleHog

dhi.io/trufflehog

TruffleHog 3.x

CIS
linux/amd64
alpine 3.24
Tags:

3-alpine, 3-alpine3.24, 3.97-alpine, 3.97-alpine3.24, 3.97.4-alpine, 3.97.4-alpine3.24

Index digest:

sha256:36f13b28e5c58bacbb07c8eab9afee778cdd9cf59b8684137fe121592f967f00

Manifest digest:

sha256:88f901e456a971805de576f00faf3f678cc98841f630cda42cc497824ee153d2

Size

32.18 MB

Last pushed

6 hours ago

Vulnerabilities

0
3
1
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trufflehog:3-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trufflehog:3-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trufflehog@sha256:cfe913a8df0ccd7a76b42958c4a655d8aa89cf85d6f3499c5b6affe94474226f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trufflehog@sha256:3711c4d90c112722be7be1127052b0c5dc888fccfe05889ccc0d5ac6fa281935
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trufflehog@sha256:6ea1d6d4a70e5e3d560e17b23b01ca78638665e1b1f82f8bf8595251d4076299
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trufflehog@sha256:e14157989f673324ec43dd1e050c4b7b8395b547825e5f1dcb428a8c2a59dd9a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trufflehog@sha256:7429be13777ce42f27c290a4089e712465654895069fae8135b2ff546e4685b8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trufflehog@sha256:f07a3f2f36171effb5f56bb989179f2a88b53a0ec6b25ca0db4b8f7263d22308
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trufflehog@sha256:0917a2b067c4a7a68539142f94221349b05cf54e1b759bed2191e22a3f9a0088
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trufflehog@sha256:1c09c05ebbb39313c97987464a390f7cf45c30ce5186214222c56f95676e4ea6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trufflehog@sha256:3943e4a19494da409140ba0c93df1ef2c68a0d92d4f6f16b65329c1f2d5a2c46
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trufflehog@sha256:4f6c35a54972205ea91e4af5bc6b0ba575e1f2bbf0632bfa9797c08156e4a17b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trufflehog@sha256:e216c333b69b1fe7ce77aabae1dec0899415bbe5057f2a26119e26c5e7f40572
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trufflehog@sha256:4a2acbfe0af8582161f1116e42da153dfa0727cdbb31d5a844e8e87906ca882b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trufflehog@sha256:f3d6e8d1ce2edae5828a31923ef312c10f8c746706509cf7d10043c53e2a2b29
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trufflehog@sha256:646b6735e8a9b97a39c277ccbc0d93aaf39fe08fe56966bcbf865817909a219f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trufflehog@sha256:dd1e2dd57eff339700167ad581963a6d191f28dc9ca3f66c6c6b3a1eebea2a12