Sign inSign up
regctl

dhi.io/regctl

regctl 0.x (fips)

CIS
FIPS
STIG
linux/arm64
alpine 3.23
Tags:

0-alpine3.23-fips, 0.11-alpine3.23-fips, 0.11.6-alpine3.23-fips

Index digest:

sha256:8a34f6824502e6d2ede3b216a9f6e3fcc939103bf41386b60fd926c5eba7b892

Manifest digest:

sha256:238f18d816b28fc131ab13e5c71fa89fbca997842c64c30a1a1d4553b9ffb494

Size

7.90 MB

Last pushed

24 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/regctl:0-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/regctl:0-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/regctl@sha256:52d56ba249e20d08da72fa5dc0c3afb2eab79ad9ebfcd426a2e9aca31fd5f8f0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/regctl@sha256:27d4af86662157546ff67f7e830735e1977c2a9e2483116fcee2fa84bb5c61f8
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/regctl@sha256:3b19441c39228165d5cee3ae289d30d17627af04a8b43e7934a08dac8f10459b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/regctl@sha256:39e2770b8e30068ad0ca01520c6f5f2d46e6bfc8e58b99339d2b692177a65419
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/regctl@sha256:b14095ae843bffdce5fcbd027422165f894d094c603441b996d32cdc197ba6cd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/regctl@sha256:3626daf2e70f3d9fbf24b6f8b6da88d55345126fc65f20ab6b5bd65aa4d1613c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/regctl@sha256:321c27c72a37ab7db0a912068a7ef3f6702d503a4f78399d7a184a714dbfee1e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/regctl@sha256:be93910f3bb3edd9952156c968e3622d8af49f56d530eabd400cbc4dd82b700f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/regctl@sha256:4d0beb95fd7a099aee21c1cd3e5001d3173e518aa126abcdf89a252aa3d7d963
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/regctl@sha256:74a1b60aef7c34acba045091d66123fa747cddb05a675f881f04db7209328013
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/regctl@sha256:4ff3abd799defa529f8da2c423c811fcb0e3b68787715aee093efc77fc25de16
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/regctl@sha256:8e8833f43595065b4a9c491c10ded712f17f65d1b47175978f41745bb654041d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/regctl@sha256:882f4ba85d2f9c54af45f5ceca0ba923e09517557e44f89548df322f18755cd0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/regctl@sha256:f0d3131bd083b829fcacbdb3a85687e76516b363a74b3bc1e9262b90c00c961f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/regctl@sha256:4d2382903c831e099836c53839833375995dc3f742de8816971124b350c66613
SPDX SBOMhttps://spdx.dev/Documentdhi.io/regctl@sha256:7ef2be7ac69ca5d3563927828597ffb668ee64c2ed70cabad2a8ca5cbccd32d1