regctl

dhi.io/regctl

regctl 0.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

0-alpine3.23-dev, 0.11-alpine3.23-dev, 0.11.5-alpine3.23-dev

Index digest:

sha256:eff33afb5daedcaad9b3cf8b72c7d1aa7ad32204acd29804070b7827d602399f

Manifest digest:

sha256:8ab3c324059c3d406e2e6eefd93fd837badc1b286a0fd4ff324c545b487677bd

Size

12.11 MB

Last pushed

15 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/regctl:0-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/regctl:0-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/regctl@sha256:8c1cbd9b33a8dd68fe92326a3cb8886457bb8c2445e5d75fc481a4f66136e72e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/regctl@sha256:92778c1fcd736210b8b1562101624ee3353078fcdcbd76dcf10410f456c0e9fb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/regctl@sha256:e02450e749670ed30c1db8176a11448af250cbb4b6fd73f78bd7587177e73b0f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/regctl@sha256:72de0fe956f34fcb0fd1894c942c000a7ace395e3d8bcacc5371d867cac7ca85
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/regctl@sha256:b79dc1bd33a735aec8f05ab8870517dca04b1d410ce7a0ca5d755a01bd282fee
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/regctl@sha256:0fe0573566b06c1ae2c006f655bb0e49d89f2787708c2f859c80ba49ce8c9841
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/regctl@sha256:fa35f71610f31d1fbb01dab586d10f53bef4701bf24953cfebb1025f12d253cc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/regctl@sha256:0cc3ec2033bddc9bc65eb30d3b4c63c5d77d776f652bc52ee94c652a3a534be2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/regctl@sha256:3150f3551fa98bd1723bf0fde0a5f6f9c5682788d4d46fdc13e8f13d786179e2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/regctl@sha256:a8dae7b1351052915c3553e89688af2ac85a307be82fd17963632d02ea9cf1d1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/regctl@sha256:503f1515ab88fd8ec7bfcb2adfb06e35d67ce4bbcc2a33a27747627688b81eb9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/regctl@sha256:9317d8c7b1266e37879ebff02a2590b66d61dffefdffe0e8667cafe198570107
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/regctl@sha256:1ee22d554210ec3f10825bcb6ccf9441535492c9eccacbca191c25de9a2450ab
SPDX SBOMhttps://spdx.dev/Documentdhi.io/regctl@sha256:4a948d02e82d84a99d2d3d60e22388738b3f46638a8e1cc5ef5424e5e1d54b4f