regctl

dhi.io/regctl

regctl 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips-dev, 0-debian13-fips-dev, 0-fips-dev, 0.11-debian-fips-dev, 0.11-debian13-fips-dev, 0.11-fips-dev, 0.11.5-debian-fips-dev, 0.11.5-debian13-fips-dev, 0.11.5-fips-dev

Index digest:

sha256:a5b894786d67003be7e7eb040a03063de57cd51353eb4a567027742bbfd75ee1

Manifest digest:

sha256:fc2c23f3574789f47370857a7d95191a295cacd6a73057b040376d04a37d3095

Size

32.33 MB

Last pushed

9 days ago

Vulnerabilities

0
0
2
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/regctl:0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/regctl:0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/regctl@sha256:c5f294f9fa15e943321d18445bad096583a7c9d42cf0214a983a4894f2c3851e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/regctl@sha256:38de7b6f4dbe09790d4df66970f6f04abe218b9b97ec92bfcc92839e1094496a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/regctl@sha256:424592154a008c2bb275798417e02c9d9df34f42c3271ab92668e0c6a22411c0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/regctl@sha256:5fd891351f1436629a1e994a0efa12386e94ec5ead9973ea3d683cf841289ac5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/regctl@sha256:73312055f3999ae23f2561c5238662c35f23ecf63d5dab776cb8b9961c71cee7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/regctl@sha256:a64f332b18425b60f2fe855b7cf1e435c380794fc51b301a002fc1d48a9348bc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/regctl@sha256:509a775bdad976d6a47f3e9d69727ceeef12fa7923b56c8a9204479e5c55c67f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/regctl@sha256:99bcface3331a9f137484a19149d694780e0c87fb8fb19f1efed07313c789610
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/regctl@sha256:f645d78ca952689e1f5ab7f4d315e6a054f70545a08dc54869de0a9dd99f8819
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/regctl@sha256:2885e5ea17f066be93f0766b28d86a69a6fa9811b3b6335ecd409d1502c19cfa
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/regctl@sha256:4307c1556e9421e82c590df47362c07f4fcbc14985915b83821e70d979fac992
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/regctl@sha256:ef94ad578904bff990b4db408c324fee079499141e283126c73ea71f108bcb36
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/regctl@sha256:2b50dcac3449620423d0684aead92c90f145e4435d04be6423a82fd061abc984
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/regctl@sha256:1162e6273a1a123e0a3be3a2c64b13246e62528e670fe697d1a9036c27fc0761
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/regctl@sha256:ef412901afa0c7982837833e90eeee2dd2c52967c06c5c42bfdfe192e9bdc83c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/regctl@sha256:1046365cbef7c9ad0ec721b95125c5e97c485c2c38377f5607e9ef292b3ab0e5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/regctl@sha256:bb49df3a2e8e4a4d9ef366161e3caf44d58afbdf8ec6f6fa0b73ad2e89f1e029