Sign inSign up
regctl

dhi.io/regctl

regctl 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.11-debian-dev, 0.11-debian13-dev, 0.11-dev, 0.11.6-debian-dev, 0.11.6-debian13-dev, 0.11.6-dev

Index digest:

sha256:bedc6383bbc2c5fc3c14038c70c792e1b38cc9849a63401790c94309fb02ae26

Manifest digest:

sha256:2ecdbd71622e5d01ed079d2ff012416b7b0f877c21a386095a4a52a6b955af7f

Size

31.61 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/regctl:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/regctl:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/regctl@sha256:c99e484927f746e21e302df265663dccb890bbae467bbce17c58f665170c9675
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/regctl@sha256:6ac752f24113dbaf51f50c6381ea82fa216cd6a2c8b920dec5e134063bc68085
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/regctl@sha256:449cc2cbae1b191f8ca89052e049998c0d96989b7a84f01b9bc080e0e6ddb6c9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/regctl@sha256:6939d1fcd3683689e2ac8932b7b33a46f2116d764c9d54b92b3804e1c11d502f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/regctl@sha256:a8c6efd436097a1e1bea024a315f049b94fc14a23f66e7f8f921a1387b420075
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/regctl@sha256:5b249c71999e24e1ba6010542ad0b84b70168d19cdf34dcf95319e7fcb5039e5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/regctl@sha256:67a837204cf6fd6060b170dba43e50dc9d5ab45713713f3d2feecd6f3e12a835
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/regctl@sha256:cbcd1ce6880d426b6f34491c65df6f2a3e5d73674ff884d4317aecaf8cf6dac2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/regctl@sha256:e222f5f77db5f56995a683851cf881978811b9011fb69fe90a8af7233e602838
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/regctl@sha256:8b17c893e284f4ac26d5e08d2ffb3c580428ed5908d5b7ce86a6b4c50eaabdfa
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/regctl@sha256:7e7f3dfb6950a28b3fb0fe00d08b633346a77d2b972f7f6c8a55645c5446d8d3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/regctl@sha256:aed7d71bf9a56aec5a7bf96d49255cd626e82ff1f0c5d850cf136c3ecb40a1a3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/regctl@sha256:db7d566af5ae8c6e5c27738aca12bf15786a98e0c77ca1c183c24c4979674521
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/regctl@sha256:3fe5081b6c9ce7f62e4279ea303fc098bb1948cfdc2f6de7fb7723abdda84491
SPDX SBOMhttps://spdx.dev/Documentdhi.io/regctl@sha256:d09a42ee3893a0c32e95bcfb500d9f1525df7e7e1d07cd1d7429f6d44d8c240a