dhi.io/regctl
0-alpine3.23-fips-dev, 0.11-alpine3.23-fips-dev, 0.11.6-alpine3.23-fips-dev
sha256:522521f9ebbab02fdae88efd47782450fd19e1d92b61763001a679570905b6a0
Manifest digest:sha256:a9b699ab438a9caf3296c4fb645b6d9c7cad9ec9dd9f13b3e73ca705d18ccc8b
Size
13.00 MB
Last pushed
7 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/regctl:0-alpine3.23-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/regctl:0-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/regctl@sha256:fe2459ed77d94da6c2bbebc27d00e7f751d9f55b7019b51e2e4dd78ca250ce47 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/regctl@sha256:e3a059149169db7a0d6f476874b255c158cbbfea70931f622a81abfbfb37c09b |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/regctl@sha256:90df66db9530a124976edc655899ffe09e15c6d42208f4861f8da58280f7764b |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/regctl@sha256:83e75ec4f792b265b54624707400b18611554a76ae1bacc435442c6672d2e5ba |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/regctl@sha256:262687006cc5747df98c717502714c6572b83a252cb1446b9c3d0081ac749a57 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/regctl@sha256:65d738d1ac43e6e4ae833ca7bf80f4f260d40d7782f5b58bbb58aaed0580b7c4 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/regctl@sha256:b6c2b0fe9335950c24e41b7eb646382d23c70d9e1782ca8a73cc2dc9e901a14f |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/regctl@sha256:64341ef4233b8d773b82ab05aa1174badcf72b2906c97f4b1dc0e4266dbdaabf |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/regctl@sha256:e38e704a8d4ae923d61458dbe49037e655205132ddc2562dc124ddd03a9ab7ad |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/regctl@sha256:4339664e3a4f847375397820f48ae92ab1539ec7f1b24d65e6c6578f550dd80f |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/regctl@sha256:02176c2a0422f93ef2f87711b311f3b4fca6682abbf93e233a2a8487fbf5956e |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/regctl@sha256:6015c4976faef072eb874defe54db20bb115372765f10352578a19b2d2a595ba |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/regctl@sha256:2a05ce7ad38bdae3234c4cb6c2edc6bc6beadf34d2ce347febc11c194c4f78d5 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/regctl@sha256:ea3ee49665286f1bf8ee6f4ebfc8d4de516c2328bea2b56f663683e192751ed2 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/regctl@sha256:7ae35e46806db7f407ef220767d15c929baa9d00a71cabd2fd4e1dd70fe099fe |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/regctl@sha256:c487ad1079f6abe3d5d2156920d0acd8dcd694d7a6f7155a5cd26df9ceb08805 |