dhi.io/regctl
0-alpine3.23-fips-dev, 0.11-alpine3.23-fips-dev, 0.11.6-alpine3.23-fips-dev
sha256:db40d88871d489a3fcff28f77e3883e15ba8e8f82863a972b56115dd8867e1ed
Manifest digest:sha256:cea2e338b78aaf09085495456ddf3a4dd8dce5dd3c828b0728c754885a7b39c8
Size
13.00 MB
Last pushed
9 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/regctl:0-alpine3.23-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/regctl:0-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/regctl@sha256:65076e9666a7396932d223c44094959f300f18f075301be316670155f5701bb7 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/regctl@sha256:9797f9c43cbedfa2c4f10fd54a363bc0b89d34d78c956d99135495e7a35b934f |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/regctl@sha256:acd4f71cc292a27e4480ac7b7e082f4ddc9887bfb8311fa57f065ae31af84995 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/regctl@sha256:52f7f4ad1a3af1c066eae5b42e0d93fffafbae7f8405a3aaea138bb0231cb7f4 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/regctl@sha256:733a6d8d9082b936d3b5e44b49f50ed40a86719f2635b44cfcabd2d9faf22139 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/regctl@sha256:afa786fc142b813f8f9ed2bcf966cfca0560a38f287070c929df0001a8c9afa7 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/regctl@sha256:5c9628f1c0a6d259c34ceb6c29b6f7532528f464b8ce0245a037643a0f08facc |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/regctl@sha256:64256fd4e86e889915cd7f0afc50878746078af385fc4b39e8c394d58b3a2ace |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/regctl@sha256:057e2173bff4a88193cdeae18c02d3508de93e3a6f2f6b4ba40ebdaf83123639 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/regctl@sha256:40bb535176916d60523f938c340054fd92d231196f944901084fc662189f2962 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/regctl@sha256:afea36dbc3a9d023a1eb48ce00b01dd9bf3cb018efd85b74dce8386a54b73e83 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/regctl@sha256:735893303a3bd89778364aea3f7fb2728fbb4c8cf2bf307f00ab3f08d297335f |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/regctl@sha256:4d87426f5571c498896611f070df481fe6d3dbce2029866f9423f0f78f1edac5 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/regctl@sha256:bb1b34bfb74be651d8414ca33cd2ffc0cbd9cf81d846c8579cddac2afc0d9e46 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/regctl@sha256:c1f5cade78c9b8b0db7d2f5cc4fef0599f33674ba1bb06e28df25bfd42e9a941 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/regctl@sha256:7e7d3ce2d29c8dfb5362edf5ed01fb2cc7b5c827a4a180695ebcfa227ea55d37 |