regctl

dhi.io/regctl

regctl 0.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

0-alpine3.23-fips, 0.11-alpine3.23-fips, 0.11.5-alpine3.23-fips

Index digest:

sha256:10852baca89fe2295685cff65dc3e1c1823c885b9fb98718db038bb29e4cb57d

Manifest digest:

sha256:f11310506acf4af226aaa08b44b689b97af1ce0e992219ae6e658116e4abde70

Size

8.08 MB

Last pushed

15 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/regctl:0-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/regctl:0-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/regctl@sha256:2fece0d0b6c5b9d6808c2fff9ad9547da0fc0d9f81df7eed30c389ff4f99160c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/regctl@sha256:e69ac7ecd38b6aef0b27fe04ece40be41c7c7c90849d62c1624d3ce72ee25529
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/regctl@sha256:495f315503d0d268b2283f9e826aa22ef48a4c0c6686449a917b7cddc9237a23
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/regctl@sha256:26dd5816399a0e0946523ab81d1bfbe479056e228014fa2a16720bbf041a1dc4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/regctl@sha256:f5f9774bddc73ab50979dd638cca443554edc5ce67d65688c0388d5121827125
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/regctl@sha256:b4bea73abdefd2cecc6f96f4fdff269e8bc138ce82d9be788562845565a98436
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/regctl@sha256:8946895d3df6e86cb1788afae82f84b59e5d634d916731e2e43844923e0fb16d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/regctl@sha256:c8d843e6590467067b030fccc624013a435aed3699d19889e817495e57ee48a3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/regctl@sha256:42553d075e189bc52c704bd277974e9df4890cfbc8a4088ff59e0bd6fa72ed4d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/regctl@sha256:422ac8c58fc85cf48cd2cb835a4d8e40e0187f058ac72403f6c0207adef9d266
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/regctl@sha256:14f2dfdb886e0fd8370e9b7cb16e1ee10c7a190ee991008d27b1e9a462e99c81
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/regctl@sha256:96f362564c350fedeeeede90e072e5ad2cff507b801ad1126ac0d110bc8b574f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/regctl@sha256:0c297f6c0c0125f49d4a691ba0772ac12028f6e2f1bb41f18b9b2b2685ecb742
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/regctl@sha256:2f7a3977b82ee0c2f29b93b3468aed4c259d75a3ec90c16b8bce9b60f2da5dd9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/regctl@sha256:69e2a4ca610c9115324e0c2e67a0c1575b1c7d314f6c082784be89d5f827ece4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/regctl@sha256:003ce8d92d3aeb426f32cceef970d52d17274ecab22ab4506e09798fb6982c3a