You can use boolean logic (e.g. AND/OR/NOT) for complex search queries. For more help and examples, see the search documentation.
Search by package name:
my-package
(implicit)
name:my-package
(explicit)
Search by package filename:
my-package.ext
(implicit)
filename:my-package.ext
(explicit)
Search by package tag:
latest
(implicit)
tag:latest
(explicit)
Search by package version:
1.0.0
(implicit)
version:1.0.0
(explicit)
prerelease:true
(prereleases)
prerelease:false
(no prereleases)
Search by package architecture:
architecture:x86_64
Search by package distribution:
distribution:el
Search by package license:
license:MIT
Search by package format:
format:deb
Search by package status:
status:in_progress
Search by package file checksum:
checksum:5afba
Search by package security status:
severity:critical
Search by package vulnerabilities:
vulnerabilities:>1
vulnerabilities:<1000
Search by # of package downloads:
downloads:>8
downloads:<100
Search by package type:
type:binary
type:source
Search by package size (bytes):
size:>50000
size:<10000
Search by dependency name/version:
dependency:log4j
dependency:log4j=1.0.0
dependency:log4j>1.0.0
Search by uploaded date:
uploaded:>"1 day ago"
uploaded:<"August 14, 2022 EST"
Search by entitlement token (identifier):
entitlement:3lKPVJPosCsY
Search by policy violation:
policy_violated:true
deny_policy_violated:true
license_policy_violated:true
vulnerability_policy_violated:true
Search by repository:
repository:repo-name
Search queries for all Debian-specific (and related) package types
Search by component:
deb_component:unstable
Search queries for all Maven-specific (and related) package types
Search by group ID:
maven_group_id:org.apache
Search queries for all Docker-specific (and related) package types
Search by image digest:
docker_image_digest:sha256:7c5..6d4
(full hashref only)
Search by layer digest:
docker_layer_digest:sha256:4c4..ae4
(full hashref only)
Field type modifiers (depending on the type, you can influence behaviour)
For all queries, you can use:
~foo
for negation
For string queries, you can use:
^foo
to anchor to start of term
foo$
to anchor to end of term
foo*bar
for fuzzy matching
For number/date or version queries, you can use:
>foo
for values greater than
>=foo
for values greater / equal
<foo
for values less than
<=foo
for values less / equal
Need a secure and centralised artifact repository to deliver Alpine,
Cargo,
CocoaPods,
Composer,
Conan,
Conda,
CRAN,
Dart,
Debian,
Docker,
Go,
Helm,
Hex,
LuaRocks,
Maven,
npm,
NuGet,
P2,
Python,
RedHat,
Ruby,
Swift,
Terraform,
Vagrant,
Raw & More packages?
Cloudsmith is the new standard in Package / Artifact Management and Software Distribution.
With support for all major package formats, you can trust us to manage your software supply chain.
trufflehog
ee8e9a0bd504644cf179fe6eef1…
One-liner (summary)
Description
This package was uploaded with the following V2 Distribution manifest:
{
"schemaVersion": 2,
"mediaType": "application/vnd.docker.distribution.manifest.v2+json",
"config": {
"mediaType": "application/vnd.docker.container.image.v1+json",
"size": 8631,
"digest": "sha256:16804f5d2b6f7aad0989760e631c787fc132ead99fff282c08104ec9363a2ef5"
},
"layers": [
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 2806054,
"digest": "sha256:213ec9aee27d8be045c6a92b7eac22c9a64b44558193775a1a7f626352392b49"
},
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 673188,
"digest": "sha256:47858aee13bf9c7c2b62cfaccdc9ce2524efef339df0c0ed8935c6587a376d60"
},
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 13002006,
"digest": "sha256:975aa27f4e8a241efc1693410f46b3d9c096c5457d25ab3a88f2b9cb699871a1"
},
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 230,
"digest": "sha256:6a71c7b1785ee86f214d01b35ce433602ca768e44d0543e73f8b5296a8a97418"
},
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 3056577,
"digest": "sha256:0002f9a00c2bf5e9c29cb0a37b5fba6b2827de51b8c98846c8bd25f208be23c7"
},
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 6982305,
"digest": "sha256:3491fe5ad5abdb84158712362e0ce8c52e6bae7db9bbb8a97374b75ba2a32c88"
},
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 5682753,
"digest": "sha256:af3ce9645c6250d8541353b966145bb70e2f9ea2660b9dfbe24d3b13118366a1"
},
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 2586439,
"digest": "sha256:7e5e72241750a9fb860590d89e5f31c1deb1384e76f909a2d54a3eaf74c39676"
},
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 912,
"digest": "sha256:59e33d1a2c79119fc110f89e9d6f6dd6deb41dc7f1216f7b7810e2d1b2e8fc27"
},
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 1482,
"digest": "sha256:0960b8e1c4060c895b4b222fe305df214e37b85ec44b68868e0c3f8a2eee103d"
},
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 4646841,
"digest": "sha256:386e8f64a1c27b6042e4862fb8560dc3d372fbfc87cc66ef1f6501a3417a2f2f"
},
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 913,
"digest": "sha256:612db2714935993204739d390d1ea31bca577d700f8cea0d246d83fdaf87977c"
}
]
}
Digest:
sha256:213ec9aee27d8be045c6a92b7eac22c9a64b44558193775a1a7f626352392b49
Command: /bin/sh -c #(nop) ADD file:2a949686d9886ac7c10582a6c29116fd29d3077d02755e87e111870d63607725 in / |
2.7 MB | ||
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) CMD ["/bin/sh"] |
32 bytes | ||
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) ENV PATH=/usr/local/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin |
32 bytes | ||
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) ENV LANG=C.UTF-8 |
32 bytes | ||
Digest:
sha256:47858aee13bf9c7c2b62cfaccdc9ce2524efef339df0c0ed8935c6587a376d60
Command: /bin/sh -c set -eux; apk add --no-cache ca-certificates tzdata ; |
657.4 KB | ||
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) ENV GPG_KEY=A035C8C19219BA821ECEA86B64E628F8D684696D |
32 bytes | ||
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) ENV PYTHON_VERSION=3.11.0 |
32 bytes | ||
Digest:
sha256:975aa27f4e8a241efc1693410f46b3d9c096c5457d25ab3a88f2b9cb699871a1
Command: /bin/sh -c set -eux; apk add --no-cache --virtual .build-deps gnupg tar xz bluez-dev bzip2-dev dpkg-dev dpkg expat-dev findutils gcc gdbm-dev libc-dev libffi-dev libnsl-dev libtirpc-dev linux-headers make ncurses-dev openssl-dev pax-utils readline-dev sqlite-dev tcl-dev tk tk-dev util-linux-dev xz-dev zlib-dev ; wget -O python.tar.xz "https://www.python.org/ftp/python/${PYTHON_VERSION%%[a-z]*}/Python-$PYTHON_VERSION.tar.xz"; wget -O python.tar.xz.asc "https://www.python.org/ftp/python/${PYTHON_VERSION%%[a-z]*}/Python-$PYTHON_VERSION.tar.xz.asc"; GNUPGHOME="$(mktemp -d)"; export GNUPGHOME; gpg --batch --keyserver hkps://keys.openpgp.org --recv-keys "$GPG_KEY"; gpg --batch --verify python.tar.xz.asc python.tar.xz; command -v gpgconf > /dev/null && gpgconf --kill all || :; rm -rf "$GNUPGHOME" python.tar.xz.asc; mkdir -p /usr/src/python; tar --extract --directory /usr/src/python --strip-components=1 --file python.tar.xz; rm python.tar.xz; cd /usr/src/python; gnuArch="$(dpkg-architecture --query DEB_BUILD_GNU_TYPE)"; ./configure --build="$gnuArch" --enable-loadable-sqlite-extensions --enable-optimizations --enable-option-checking=fatal --enable-shared --with-lto --with-system-expat --without-ensurepip ; nproc="$(nproc)"; make -j "$nproc" EXTRA_CFLAGS="-DTHREAD_STACK_SIZE=0x100000" LDFLAGS="-Wl,--strip-all" ; make install; cd /; rm -rf /usr/src/python; find /usr/local -depth \( \( -type d -a \( -name test -o -name tests -o -name idle_test \) \) -o \( -type f -a \( -name '*.pyc' -o -name '*.pyo' -o -name 'libpython*.a' \) \) \) -exec rm -rf '{}' + ; find /usr/local -type f -executable -not \( -name '*tkinter*' \) -exec scanelf --needed --nobanner --format '%n#p' '{}' ';' | tr ',' '\n' | sort -u | awk 'system("[ -e /usr/local/lib/" $1 " ]") == 0 { next } { print "so:" $1 }' | xargs -rt apk add --no-network --virtual .python-rundeps ; apk del --no-network .build-deps; python3 --version |
12.4 MB | ||
Digest:
sha256:6a71c7b1785ee86f214d01b35ce433602ca768e44d0543e73f8b5296a8a97418
Command: /bin/sh -c set -eux; for src in idle3 pydoc3 python3 python3-config; do dst="$(echo "$src" | tr -d 3)"; [ -s "/usr/local/bin/$src" ]; [ ! -e "/usr/local/bin/$dst" ]; ln -svT "$src" "/usr/local/bin/$dst"; done |
230 bytes | ||
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) ENV PYTHON_PIP_VERSION=22.3 |
32 bytes | ||
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) ENV PYTHON_SETUPTOOLS_VERSION=65.5.0 |
32 bytes | ||
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) ENV PYTHON_GET_PIP_URL=https://github.com/pypa/get-pip/raw/6d265be7a6b5bc4e9c5c07646aee0bf0394be03d/public/get-pip.py |
32 bytes | ||
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) ENV PYTHON_GET_PIP_SHA256=36c6f6214694ef64cc70f4127ac0ccec668408a93825359d998fb31d24968d67 |
32 bytes | ||
Digest:
sha256:0002f9a00c2bf5e9c29cb0a37b5fba6b2827de51b8c98846c8bd25f208be23c7
Command: /bin/sh -c set -eux; wget -O get-pip.py "$PYTHON_GET_PIP_URL"; echo "$PYTHON_GET_PIP_SHA256 *get-pip.py" | sha256sum -c -; export PYTHONDONTWRITEBYTECODE=1; python get-pip.py --disable-pip-version-check --no-cache-dir --no-compile "pip==$PYTHON_PIP_VERSION" "setuptools==$PYTHON_SETUPTOOLS_VERSION" ; rm -f get-pip.py; pip --version |
2.9 MB | ||
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) CMD ["python3"] |
32 bytes | ||
Digest:
sha256:3491fe5ad5abdb84158712362e0ce8c52e6bae7db9bbb8a97374b75ba2a32c88
Command: /bin/sh -c apk add --no-cache git less |
6.7 MB | ||
Digest:
sha256:af3ce9645c6250d8541353b966145bb70e2f9ea2660b9dfbe24d3b13118366a1
Command: /bin/sh -c pip install gitdb2==3.0.0 truffleHog==2.2.1 |
5.4 MB | ||
Digest:
sha256:7e5e72241750a9fb860590d89e5f31c1deb1384e76f909a2d54a3eaf74c39676
Command: /bin/sh -c apk upgrade expat |
2.5 MB | ||
Digest:
sha256:59e33d1a2c79119fc110f89e9d6f6dd6deb41dc7f1216f7b7810e2d1b2e8fc27
Command: /bin/sh -c #(nop) COPY file:4459b0b4df22e447e57dfe6482762144ce23117ce927e710b6741c1db953e498 in /entrypoint.sh |
912 bytes | ||
Digest:
sha256:0960b8e1c4060c895b4b222fe305df214e37b85ec44b68868e0c3f8a2eee103d
Command: /bin/sh -c #(nop) COPY file:f555784eca50029a98a68da8f8acdbf29ae1712ee8706683e6990bfc5e108bb1 in /regex.json |
1.4 KB | ||
Digest:
sha256:386e8f64a1c27b6042e4862fb8560dc3d372fbfc87cc66ef1f6501a3417a2f2f
Command: /bin/sh -c #(nop) COPY file:89eab4c1897dd3e64e5c0467069fd2dadc697eefd898d0eaf518d0428be16b2c in /bin/git-credential-myob |
4.4 MB | ||
Digest:
sha256:612db2714935993204739d390d1ea31bca577d700f8cea0d246d83fdaf87977c
Command: /bin/sh -c chmod +x /entrypoint.sh |
913 bytes | ||
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) ENTRYPOINT ["/entrypoint.sh"] |
32 bytes |
![]() |
trufflehog |
15538 |
![]() |
||
![]() |
trufflehog |
0 |
![]() |
||
![]() |
trufflehog |
4 |
![]() |
||
![]() |
trufflehog |
1 |
![]() |
||
![]() |
trufflehog |
1 |
![]() |
||
![]() |
trufflehog |
0 |
![]() |
||
![]() |
trufflehog |
35304 |
![]() |
||
![]() |
trufflehog |
0 |
![]() |
||
![]() |
trufflehog |
0 |
![]() |
||
![]() |
trufflehog |
0 |
![]() |
||
![]() |
trufflehog |
0 |
![]() |
||
![]() |
trufflehog |
0 |
![]() |
||
![]() |
trufflehog |
0 |
![]() |
||
![]() |
trufflehog |
0 |
![]() |
||
![]() |
trufflehog |
0 |
![]() |
||
![]() |
trufflehog |
0 |
![]() |
||
![]() |
trufflehog |
0 |
![]() |
||
![]() |
trufflehog |
0 |
![]() |
||
![]() |
trufflehog |
1 |
![]() |
||
![]() |
trufflehog |
0 |
![]() |
Last scanned
2 years, 5 months ago
Scan result
Clean
Vulnerability count
0
Max. severity
UnknownThese instructions assume you have setup the repository first (or read it).
To pull trufflehog @ reference/tag eac8b5e37e1b95bca7249f099230ae190d3002f4:
docker pull docker.myob.com/appsec/trufflehog:eac8b5e37e1b95bca7249f099230ae190d3002f4
You can also pull the latest version of this image (if it exists):
docker pull docker.myob.com/appsec/trufflehog:latest
To refer to this image after pulling in a Dockerfile, specify the following:
FROM docker.myob.com/appsec/trufflehog:eac8b5e37e1b95bca7249f099230ae190d3002f4