regctl

dhi.io/regctl

regctl 0.x

CIS
linux/amd64
alpine 3.24
Tags:

0-alpine, 0-alpine3.24, 0.11-alpine, 0.11-alpine3.24, 0.11.5-alpine, 0.11.5-alpine3.24

Index digest:

sha256:d637aea7c44b210ac30d530cb0a8646ddfd32d51c86f1cd81388e859b7a5e8f0

Manifest digest:

sha256:9127203cfe517109789f651693871b3d9d979ede82ff9d1ed1cce8575b0fccbf

Size

4.69 MB

Last pushed

15 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/regctl:0-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/regctl:0-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/regctl@sha256:41ff549c8029c9d992a84d1e5109655eae82dd70367956e5c56bc7757628a1f7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/regctl@sha256:15b0f9957ad3b3789a004bad0eeb77b74527dd7d249b8e3213caf580a25a54b7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/regctl@sha256:11dfc082c9d4aefff981f92da498fbea11c3b630030afd8028cfb56294757cea
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/regctl@sha256:d6778c5311c12c062513086bb6d7af96121dbc9ba3588414f2c3838753ee5e9e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/regctl@sha256:2a253ec0b9635a1a16c8eecd0a254bae84b005e5d3467ffe54553da3652c69e3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/regctl@sha256:7a33592c8d28a097189b58c5b1dc85c44c4e011d68b3300044e7e0185bbc737a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/regctl@sha256:629b1b71e58c1b00ca415eb48e22276c653f09d1735e92d6ec25a7c6066dd801
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/regctl@sha256:29ec76d3b9b8baeadbb758be7857ce14b7e4398543047a766676c521db3c857a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/regctl@sha256:adc98ed3e1680c046d62a5b1f1934818ab180a633eba4f426c74646f06c76e54
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/regctl@sha256:9b6924d1ce70fad83e71576f6e1fb0a58cb1fe8dd4d720347a7d8110ce416442
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/regctl@sha256:a9d5b4cda0447e0d79d63145e65b2c078cf6f6d23ffcb98cca2e2e37e4e0bae7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/regctl@sha256:7ce8de5ea803ea8a5bdf2fa93aa7f9593cb4ae85d110436978f76506fbae1b9b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/regctl@sha256:b596e645b0fea82a3afe67727b726977f1d7ae5bfa75808f85b2b13e32b467ff
SPDX SBOMhttps://spdx.dev/Documentdhi.io/regctl@sha256:4e5913e07b77dcc1c72b9844cf6ef366eeafc72663539fccc990bb34329cf5ed