dhi.io/trufflehog
3-alpine, 3-alpine3.24, 3.97-alpine, 3.97-alpine3.24, 3.97.5-alpine, 3.97.5-alpine3.24
sha256:4d862cb8d55f33853ac91b91e3381b8ee60d891b1d10eea471cd4bc8e4f581ff
Manifest digest:sha256:f4c91aed8712d8ade1cebc14c8a764c733a7cf1156e3af8fe8f903ec8f535f9b
Size
32.52 MB
Last pushed
8 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/trufflehog:3-alpine2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/trufflehog:3-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/trufflehog@sha256:fd6419b992bddadd384e9a48e5d9ced75e1324088ef2a454b746af0e11c61a0a |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/trufflehog@sha256:11dae8039ba97395a5a43caeb80ab102a17505940aa49e72fcebfa5d2358de12 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/trufflehog@sha256:54af087da670f8bdceeda3f3dd17107b55151008041cdeef5c5cc9fbe1a1d820 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/trufflehog@sha256:bbc1f7a5748bb4ceb2832e80db88337261017c17fab01abf0c63591c5f6082be |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/trufflehog@sha256:d128e109a0919e069e0d8ed954092fe0115da44390d2aa1e3f1dba4f44c0b500 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/trufflehog@sha256:34e533995771e96d56e52f84a02ad3227bb55fc0c44d66f7d36a1e6dfdcd4527 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/trufflehog@sha256:562e157d924643c858310c25f83b49864e26eb04ed9263ecf15ccdc74cda2938 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/trufflehog@sha256:6eff56353a33d8eaac87453a69d8fa6bb84267f9717d996bb750122dd5542a3e |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/trufflehog@sha256:0c3b47bdc20b90d96d7dc4317af12f3ae1685a2dc795b45f27ca797909ee92e6 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/trufflehog@sha256:c5b485b3a62a9e27f3b1070c758a1ab55fee2cb5a3afd44d3961e63bbd2244ba |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/trufflehog@sha256:448d799831f4f246b6121e04091f1151be7c2606f58c2f26f622b36bdbab121e |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/trufflehog@sha256:e94bce9ce1adf9bd1ffc34393aa63f1584a16130ff78f6abe72fa885166cfa28 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/trufflehog@sha256:9b0c5923fc8b3b6513d997da9ca0a15115dccbd88eb5660db59b5f1e4e1b0e95 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/trufflehog@sha256:d4947e813676a6f83c469841c8f2cbdd16b99ce164a0ae2b00b678972a9e8148 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/trufflehog@sha256:8c3ed545382cdcaba839f486781a114f6c632e1d317b4a94264a3ec52f594119 |