regctl

dhi.io/regctl

regctl 0.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

0-alpine-fips, 0-alpine3.24-fips, 0.11-alpine-fips, 0.11-alpine3.24-fips, 0.11.5-alpine-fips, 0.11.5-alpine3.24-fips

Index digest:

sha256:b99692a71e972396d3d5b94c3c2493069380840f420603120610ae42238be4b4

Manifest digest:

sha256:2288b0f661ede6ff2bb48c3038efb63fc7e6d2774b54d2b53951d7905fd359d4

Size

8.08 MB

Last pushed

15 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/regctl:0-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/regctl:0-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/regctl@sha256:c6f900eb81b97ce8d67a8fef62ac3c71ddeb5324b7818c771be385cfeeab791e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/regctl@sha256:27ff8fa3cd017b28c5a0099455fe5e74c34b5c74adb781a81559ed53b4330745
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/regctl@sha256:9ff6e33e49cc63b4690604ff9c79dc59f54dc326447aaa965f9317f547b75ed0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/regctl@sha256:e146276842c6e9e5c6de4b018e2ac8e2b5f3f946a0e0f31840fdbc0cd14998ad
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/regctl@sha256:38a77e4296fd861b05336fa5f724ac9875dc4ce968c19e9d5a9734f6ddd9e347
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/regctl@sha256:fe03b45e9fb9119b780ab35ccafacdfdf088b5fb979fe9c6d14b9856ee5813b1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/regctl@sha256:dc16d961e12960ebce7c550efbfca2ebbf5cc86e6c6ea9cbe23be9da724c5cf2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/regctl@sha256:61d42127b78f8ebf2d11ff0785c1dff170df7d6393af14a5e5a9028c953bd4c0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/regctl@sha256:ce651e1ec8da0cb148cf66f33b1de645bd20ef4c0f2f7c59da5a049f898b9d7d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/regctl@sha256:6318c7633dec9cb7f1ab745c05c5e8f31b7384aa346838a553500392ed758d87
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/regctl@sha256:457bc9e2aacf9056502c0e4cbf5458e436307c23d8036bea4f905048c27edbc6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/regctl@sha256:f897323351d1063963257702b51a2cbdda20e6f4d3f3920241d7c60e846f88ce
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/regctl@sha256:5d93f7a2f33e5f1222a4bbbad0606cdfe50500fb0ce1b3a853f3e2815ebcd1fc
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/regctl@sha256:5fc1b4dabbccfb2a9853d84ab7c9fe74bed1e44a9b5a8c7e6f14c305dc602939
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/regctl@sha256:2e63641fe518064820ed511ae99dcbde52fea8f039680ebc60306bff56b25be1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/regctl@sha256:c6386d7ce138d681333803c4c1b8d6a557809bd3ecd025551621bea50847f45d