dhi.io/regctl
0-debian-fips-dev, 0-debian13-fips-dev, 0-fips-dev, 0.11-debian-fips-dev, 0.11-debian13-fips-dev, 0.11-fips-dev, 0.11.6-debian-fips-dev, 0.11.6-debian13-fips-dev, 0.11.6-fips-dev
sha256:05011323f9df5b23f49a9db4858ffbf32830858cf9cf12aa81edfafb41ecc135
Manifest digest:sha256:22a9f3e689242815445f52bcc09c79890b904d04f8b0346a1722c6dcf19b8440
Size
32.36 MB
Last pushed
9 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/regctl:0-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/regctl:0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/regctl@sha256:1bc3a325b223f3d0615c7cfcc432cb93473de671227f7a2c06d42263713037ca |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/regctl@sha256:780c7c8f26813377081f2b9316f292ba6b4ac97a284f712a25bd392ddbb90067 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/regctl@sha256:28453fa0fb0b58f62337fbfb8abe0ac8870a02f3d190ec09572871e48e9b6d57 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/regctl@sha256:c01e43bd4048b10e0ac5e313ee2fdc85810e13af50835d17f73bb28b9783f30a |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/regctl@sha256:35f9665265598f8891c9bc5c03682cc6ca969240999d58f355b68c1e461bc725 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/regctl@sha256:848acd617d3460c021daa06645bc96e1f335588a1800b967eabb6061482b47aa |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/regctl@sha256:2461f05c9f200462c8363c3c14f63c986588486f2ddb88bd4c380d782553b174 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/regctl@sha256:885b426b989d9e2f92868add19b5a6d9b827a3cdbf19eeff161b2706e6342dc6 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/regctl@sha256:a83f8ad8b6aef597238854fa552769446cf99f5d2f391a181039f623e5fe54b3 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/regctl@sha256:03b1913a2ba41a4c8180fdabc83bcfd68cbbcf4958c445a9d54ce0ea6b0aebbb |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/regctl@sha256:a3ce22994fd695e7079fc034e89a9ce8b95b6cacac801b3e4bc33c3eee78cc61 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/regctl@sha256:12b16688db2c1d24a9903bd47a84fa71435a851c8e237e31c6e09b7b749d45aa |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/regctl@sha256:c4b4b252eff765efd56b9bc77951984a1dfb67a255175f3d42592ccd6f1fb7de |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/regctl@sha256:781e101fe8ed4503b96f435ca0570a4dd1938f0ed549dcda82bd31c565814e26 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/regctl@sha256:d3a08062da7abac911b3d647208006b8b4f991b1392ef977f68c7ba927b8876c |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/regctl@sha256:445594bc798a0a9cebb2dd5b42b5feeb192cacf4f5c4c495fa108046b71686a3 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/regctl@sha256:2a1e4be3d79a6cd4c8acda1243089af86d5f146c8c961cc9b68b65db70b03a5b |