Sign inSign up
regctl

dhi.io/regctl

regctl 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.11-debian-dev, 0.11-debian13-dev, 0.11-dev, 0.11.6-debian-dev, 0.11.6-debian13-dev, 0.11.6-dev

Index digest:

sha256:a785f42242dfd119118d6ef4fb3102edb7efa6f447537d3da385342a1f38157a

Manifest digest:

sha256:0b41ec27ccaa662bd132c120ca8efa69992eeffc0630cf1aae63f164027f4857

Size

31.60 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/regctl:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/regctl:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/regctl@sha256:190f3a1c43f2a726a5b9f364cea56630455f063d4655554f5b7471fdf535a896
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/regctl@sha256:68aae32caf8d4fe5c3d6dfe934bfbaa1edf368d91355e009f537d3247e80e932
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/regctl@sha256:55bcc16663be657888c82776d9cbeac2ff5b759a415e88c00b83061d6a67d37c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/regctl@sha256:6d398d77fd6e220b20eee81068474a9b1937cee4222393c15f22910786ec0ba4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/regctl@sha256:10de824c0174194eacc15bd32104780669dbad9375fcb6cf5d6de89bf5cbb9fa
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/regctl@sha256:5ad6f67d2942d9a9640d3ec0bac24129d4532ed8f7cf34f56c9865015e01b787
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/regctl@sha256:7e175dd82dc07b15e0510c6a3187d222f5cdabf4f7cce932df2e50237fc6866a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/regctl@sha256:360607a053288cc3e7b55df2ac007e7f6a420bc382d115c44662eb05e9c4cefe
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/regctl@sha256:1730df8bd5c22178d1754b921ef30edca981995221b9ea1ee341452c378c107d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/regctl@sha256:c6f9bc9628d173d99210edcf5b8a1c48e6c6a98d96f5de3448570754564845d8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/regctl@sha256:8342f94aa2e91fb66ceda2a7ef622bf6668fb6cefacf7885f3f11c18df0ccf20
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/regctl@sha256:8cd08c6e2d94ff07ff7753ccc3eb8097f43474e980d677a11af8567b729c6fcb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/regctl@sha256:581f46a9324076eede47e20b525ca7fee93a3d29eb1bab69a1eb21ad17b08706
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/regctl@sha256:dc25407d3fde8d004fdad0fc23d302ef870c7d102872222975385e6f71cb9383
SPDX SBOMhttps://spdx.dev/Documentdhi.io/regctl@sha256:3e6f57b0ae27b161828b060b06ef16129688396efb86a04d1cbd2739fa6719ef