dhi.io/trufflehog
3-alpine, 3-alpine3.24, 3.97-alpine, 3.97-alpine3.24, 3.97.4-alpine, 3.97.4-alpine3.24
sha256:36f13b28e5c58bacbb07c8eab9afee778cdd9cf59b8684137fe121592f967f00
Manifest digest:sha256:88f901e456a971805de576f00faf3f678cc98841f630cda42cc497824ee153d2
Size
32.18 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/trufflehog:3-alpine2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/trufflehog:3-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/trufflehog@sha256:cfe913a8df0ccd7a76b42958c4a655d8aa89cf85d6f3499c5b6affe94474226f |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/trufflehog@sha256:3711c4d90c112722be7be1127052b0c5dc888fccfe05889ccc0d5ac6fa281935 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/trufflehog@sha256:6ea1d6d4a70e5e3d560e17b23b01ca78638665e1b1f82f8bf8595251d4076299 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/trufflehog@sha256:e14157989f673324ec43dd1e050c4b7b8395b547825e5f1dcb428a8c2a59dd9a |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/trufflehog@sha256:7429be13777ce42f27c290a4089e712465654895069fae8135b2ff546e4685b8 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/trufflehog@sha256:f07a3f2f36171effb5f56bb989179f2a88b53a0ec6b25ca0db4b8f7263d22308 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/trufflehog@sha256:0917a2b067c4a7a68539142f94221349b05cf54e1b759bed2191e22a3f9a0088 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/trufflehog@sha256:1c09c05ebbb39313c97987464a390f7cf45c30ce5186214222c56f95676e4ea6 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/trufflehog@sha256:3943e4a19494da409140ba0c93df1ef2c68a0d92d4f6f16b65329c1f2d5a2c46 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/trufflehog@sha256:4f6c35a54972205ea91e4af5bc6b0ba575e1f2bbf0632bfa9797c08156e4a17b |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/trufflehog@sha256:e216c333b69b1fe7ce77aabae1dec0899415bbe5057f2a26119e26c5e7f40572 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/trufflehog@sha256:4a2acbfe0af8582161f1116e42da153dfa0727cdbb31d5a844e8e87906ca882b |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/trufflehog@sha256:f3d6e8d1ce2edae5828a31923ef312c10f8c746706509cf7d10043c53e2a2b29 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/trufflehog@sha256:646b6735e8a9b97a39c277ccbc0d93aaf39fe08fe56966bcbf865817909a219f |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/trufflehog@sha256:dd1e2dd57eff339700167ad581963a6d191f28dc9ca3f66c6c6b3a1eebea2a12 |