dhi.io/socket-cli
1-debian-fips, 1-debian13-fips, 1-fips, 1.1-debian-fips, 1.1-debian13-fips, 1.1-fips, 1.1.174-debian-fips, 1.1.174-debian13-fips, 1.1.174-fips
sha256:965c44f2c93a38f1b015268ceb567e1bd0bc007f6e1f3b807b257628a1b1708f
Manifest digest:sha256:c5c207fde2df330a71480470e705b8d7dfec5869152b393326f54ebb68836830
Size
47.11 MB
Last pushed
5 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/socket-cli:1-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/socket-cli:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/socket-cli@sha256:29c684054566d2325e7d60b0875fbaac8472fd83220993a0313a30bae914baac |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/socket-cli@sha256:ac39c2aef31d853f0838cc7bbcc4d5ae150c22c4ea928f199cddbb8bcd8877f7 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/socket-cli@sha256:aa438af9616332d391564ac94be75bc3506b849d008cf271d433fedd8b7f642c |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/socket-cli@sha256:0e65d40bbfa4426149f5826c1d6e44dddd6d4db0c7b0c6b21ecde10f859c33cc |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/socket-cli@sha256:3e4ec4d3317cd720fb1f123f43d877168fc7c547c5324bfcf779412b0e82eb71 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/socket-cli@sha256:7cfc23c25b97b74a984ced17217166c762475ced9cf4988c4a67c5afaabce581 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/socket-cli@sha256:724baca8b4d0957798dd0dac5372dad5042a7dad28967ce996c242df27b30e1b |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/socket-cli@sha256:9b955e7ee6de5e52315816426168573ccc11532dbc98ec1ea12c9a7f03b0c64f |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/socket-cli@sha256:8a5eeaac9b9165993732fa86e9ec440d39b675eae7043fb10f47629bf10786bd |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/socket-cli@sha256:9fc7a8fd32d43ddfeae6d647755b9ec386621dd7a4b7eb90c528d9cbd3986842 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/socket-cli@sha256:f123188d6a4433ae2e321ce02570e9e0198163677f4b690c25c0574940b06409 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/socket-cli@sha256:96e178f0acdb19d4fccc298af0029f8f59449dc1eafc211bf4805d2751f3407e |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/socket-cli@sha256:763ed1ac7ac1ad82c6a2527575f1da98d3b033ba25a06e9d3825543ab889cf46 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/socket-cli@sha256:0d438ccf9b57b0fe323b2fe0589b7f5b5ffbe58eca72db77efbf5f5122fc9758 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/socket-cli@sha256:e8192a76ffb61921380f5f4116f04f3e87969611509e063e99cbe2d71e6f1abc |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/socket-cli@sha256:5a0defa942cdd5abb0dff57cc94e5bc214e23e815e384d86e6c7f96adb20dd9e |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/socket-cli@sha256:14a6156868938d639e0822aed714f7dfdef28267c0555fa085907304a6af39c5 |