Sign inSign up
regctl

dhi.io/regctl

regctl 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.11-debian-dev, 0.11-debian13-dev, 0.11-dev, 0.11.6-debian-dev, 0.11.6-debian13-dev, 0.11.6-dev

Index digest:

sha256:386e21ca52fa428f5c7ee32ffe4b94fc76e13d13b61181d15873f641ebb6d16a

Manifest digest:

sha256:09653a2fbec9d796f164a7e775e7a921d9690191bad07e64ceb63996614167c3

Size

31.60 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/regctl:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/regctl:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/regctl@sha256:394faa9d4e57b4f7b7c29488744044969c30e3fef0c54a1261ead7210d7bd812
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/regctl@sha256:f9347d874e3f1e401918a1c89d75fca213695eac3b1744e3248a516daea1ca21
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/regctl@sha256:b77804397de9c637868216a52a65477ca3c416ebbb9f4ebccf053f8dec9d5556
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/regctl@sha256:d723075ffef21c06b984b55d84951f8ec4ef6d53720c0acc444acbf122472c19
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/regctl@sha256:f1b298537bb465e53b5aca4593b75928fe845308c34454fabdf4c6a1f1dbf12a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/regctl@sha256:571a7e64eeb1cea6532f29fb2f2e5289971fce12fe4327c566ef5e6def1cb55d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/regctl@sha256:cdf383a072198463ef1d75f6423da836a4a4c6bd8f78294f64800b61e8aaec10
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/regctl@sha256:cf1ade56479cd3b27e0419a202339ac3a23c295d85427dbef526c2a2922997eb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/regctl@sha256:b24ebd472b58aa6435410da1d023ffa662c01dd4c34d4e766513a8723c36b354
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/regctl@sha256:dc6b23804d7cfe634994d9c5a6dc5a06cff69e9c800bbb546ec6d7f12bf7f30b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/regctl@sha256:60582cad5e0eb579fa27b6c4b5747a14ff36d6e29184cb9d8ad6eaa47c63c07f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/regctl@sha256:0ddf1b8e1b839281f3fb089cb69da74f23f718d02ea0b0bfb33aa6a2cdff0dcf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/regctl@sha256:d499d2a9e068a2f6f6ba07ad126d12dc61acaf85ea6d53da35ab4d236ca71d98
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/regctl@sha256:07b92d78691f218499b7ed13b14b6c57d3e02d06a6aa7b8017e4dafcd28a8f85
SPDX SBOMhttps://spdx.dev/Documentdhi.io/regctl@sha256:bfc430a2190235616974586986e2d800a6d00a80a0e0a266a128c36c4ff29ce9