Sign inSign up
regctl

dhi.io/regctl

regctl 0.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

0-alpine-dev, 0-alpine3.24-dev, 0.11-alpine-dev, 0.11-alpine3.24-dev, 0.11.6-alpine-dev, 0.11.6-alpine3.24-dev

Index digest:

sha256:e46af2bb3fba790bf75354da3b5a6990690c645a0554ca26ae865dd261a80e36

Manifest digest:

sha256:0da7c2bf4e4ea9d709993f96665eb9948c153f99f5561c529eae3168165d9acf

Size

12.17 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/regctl:0-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/regctl:0-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/regctl@sha256:91b124be583ba439fd31fdd6eccf0f09990aacdba9f4a22ca9454f27a8afa109
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/regctl@sha256:2515c75e3cfd55849120c1c9b3baa8290d12edf0c8ccd6f0b276775d95d7904f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/regctl@sha256:bc360e900cef3a22e2769e3f7b49c2c7600a2f0ed0bae79e6109f766fe3db217
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/regctl@sha256:dfc3c472fef9ad33234c18a010f5e2b7dfa336b45f631041c510f929b97a06f6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/regctl@sha256:bc14b6990a314a12c138190855f669987480c5c6127dfd4bdb05d52576afd416
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/regctl@sha256:ce98985bb41ad9dd581f2239637c9732059d76ecbfd252d704bf0ed21c2b6e26
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/regctl@sha256:e2ea3e8101978763f7e65e86820d07e779e3b6c663ec00e4701f84fa10f6df0d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/regctl@sha256:6820f0670caefb0e8a25ca4549c0cdf6ba38fe91960fecf0272dd16a55304388
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/regctl@sha256:845e5c71622da1c30334bb76df04d1c9cb999200682fd1170cbeaca9968c20da
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/regctl@sha256:ee900dc3b2b69308a79dd0165ee452bbe28ee28b1a60604a139b9df27ba3a9d9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/regctl@sha256:cd3002071dd4fe83399f51043b274333e86481534f307bc4fce87cdac4a30b09
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/regctl@sha256:79af51d1cf49b4e7591aa5a52509d45d5b1de3f895010d1c8adf492af0610605
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/regctl@sha256:a96b20a18d6a6399c60858f28800fe1cd0adb886a0b3059289c4c42c92d9b3be
SPDX SBOMhttps://spdx.dev/Documentdhi.io/regctl@sha256:6b58525652c480e62876703d230955b211d8277ae215e3041218e362ff1ebf5a