regctl

dhi.io/regctl

regctl 0.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

0-alpine-dev, 0-alpine3.24-dev, 0.11-alpine-dev, 0.11-alpine3.24-dev, 0.11.5-alpine-dev, 0.11.5-alpine3.24-dev

Index digest:

sha256:07b9569c6d1ccc5b04e0aa0b388337a830fe3a848d25a0017337f0d5cf4267ad

Manifest digest:

sha256:082b7bf9bdb5f5eaeb0cc6c054173b44b09fb80ad4e0f41ff0e1adb5ee91d715

Size

12.12 MB

Last pushed

15 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/regctl:0-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/regctl:0-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/regctl@sha256:c9aa74572e861dbb248baf0cf22d4d205a3123cc984fd01ca2b27c584ebcd38d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/regctl@sha256:8e08d10e643a7c14314abe7cbabb578cd9e19869336e7cb6741eccdc15a3ecbe
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/regctl@sha256:0c43d33a9c4aa94b3998816f66ae460ef22c1b1540ab309c7d9c83183a651b0e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/regctl@sha256:5739a0304768ab17541097f24da5fea231049258829bb6dacbc2ba8e444efabd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/regctl@sha256:5777b566d0642fbdfc68dd9e1b719036dba3161ff5d7bb1dd9c87223421d2be6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/regctl@sha256:48845147a363ed3e136205206f87a28e52b732fc1d26bd7cf1d073ff3d559d0f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/regctl@sha256:f2fc800a9fa07365bc62acb314d1c869ff8bd0f069e2110d29e41b62afb97f1c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/regctl@sha256:cb599a29208121448de298d1d74c241b85657ced8723ea70867168b47fc602a4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/regctl@sha256:023b5b10c224850fd5f228f7088f2924f1036632be1bfa23d5c847d0363817b6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/regctl@sha256:a0a39e7f314649475b043c3b543870f566937185ee25d63a0e9a214d1a5b97e2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/regctl@sha256:97a76831a4f135e2f4a1c40ce21a15e8e325331448adef22eefdd8c5de4c5711
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/regctl@sha256:129715d49b6b833047badc3fd42c43dba0689570ef73471d580b0223322c226b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/regctl@sha256:f6cdd2f3be9626a19b87ea6b516be066ac76a161f9ba7ea4ae6fa8c9358b7856
SPDX SBOMhttps://spdx.dev/Documentdhi.io/regctl@sha256:84a9036f128d95f50a193bafc09ed4975ec060f5cc489542453e78f919908c8a