Sign inSign up
regctl

dhi.io/regctl

regctl 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.11-debian-dev, 0.11-debian13-dev, 0.11-dev, 0.11.6-debian-dev, 0.11.6-debian13-dev, 0.11.6-dev

Index digest:

sha256:1e0d97752e0a0d571d5e2bc536be3edac45c9f3cbf5e7c9b201673746479dde5

Manifest digest:

sha256:6b61b65a97c800097f7b8ec37a03396b8ec725072dc8aecabef5d6ea9c8bd7eb

Size

31.59 MB

Last pushed

4 days ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/regctl:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/regctl:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/regctl@sha256:59afce8996505455dc49b8cd5eab66190fa70b9cb7344abb40031f7f417ed98c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/regctl@sha256:d6a32ff2560d7561e95a2780dc470ff4bb3be3a531e11e2c5bef552a8fcdfd1f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/regctl@sha256:2673648e212c5ec52df8027a546e6707916bb41371ef9b3f49e848677e5acdd6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/regctl@sha256:e01b3f378586423b92806bba3b4ace7635f76a833f1b3004a5aff6316e1ca882
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/regctl@sha256:c4bf8b60a06a2e85c20450325ad87818c4492a97511c2ef28586c8b9242e4268
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/regctl@sha256:cadbc5aba417f7453d01d204bd03b5c9445157c2cc417c796fc000756e4b2cda
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/regctl@sha256:f83ff14dc1ddcfe92527500604cd41802595ed2fd6b59bc708affcf4040fc9fc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/regctl@sha256:8d19c1a1e86c55b12f11eed94a174975a2f68291e6a8a1353cc5b19069e3ce15
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/regctl@sha256:452807108fe3c855dcd0ae9ff99d7c5b4152c50a14646d7497debcc157286e39
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/regctl@sha256:e6ba5661dca11256b4e43201fc5d33596c89b5714990fdb08593d6f6086291d6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/regctl@sha256:82cdbc6f0da46804811c078b3e480b696ced6f5892ba0a769430f3c4fba4f546
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/regctl@sha256:8d3faf3e514bd901a728607ee01c370c7e3e93716b4f59c35810e42bb217e7b3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/regctl@sha256:5458bfe88d569a23230d936cd3fcaec7c96bf63b039fff2f63b3efeb7365c686
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/regctl@sha256:efae89e507fdb8e8c15a92daae68d092f64a900777d8e9a8bfeffe222810cbc3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/regctl@sha256:c2baca73b1469524a1be6c24429ddf0a03c680d21d9fb5238c3b72b6633c232e