Sign inSign up
Socket CLI

dhi.io/socket-cli

Socket CLI 1.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips, 1-alpine3.24-fips, 1.6-alpine-fips, 1.6-alpine3.24-fips, 1.6.1-alpine-fips, 1.6.1-alpine3.24-fips

Index digest:

sha256:067cc09e8c2327fdf229b692923492e7b1e0f41a05cd290f8c78c143af08be6f

Manifest digest:

sha256:23fb0aca0a9dc8d946675aa262e45850cd55b1d351f1c4f6b0c1925d34b2f372

Size

44.81 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/socket-cli:1-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/socket-cli:1-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/socket-cli@sha256:cbb4cc31715774df1ce4e81d8d89eedd3977d5c3c536e236cdf0f1105c5bf153
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/socket-cli@sha256:8469b1b14dc144b415625937431c2153a45ace5d21219da7f1a87c68c9134231
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/socket-cli@sha256:3ed15cd1326cdf6d6553c410b4ad3dfdd0a2f1f790d30f937dd25b553ffb590e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/socket-cli@sha256:91330958186b7198eeb1d75b35069c606840686a335798511fea64416e74587b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/socket-cli@sha256:857c92e0591d756bedcf1a934e3244ef4b811f08a369b9f1e758695ea5608e1c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/socket-cli@sha256:7154c71d755897cbecc60cf135645edceb9fa1744dc8c7e5d49227269d9e1e22
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/socket-cli@sha256:80d699d400572fde69e2a2de0cd68335b227c9a37d37f2c1018e98c89efaab6d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/socket-cli@sha256:f932ee558731823abf832353620047472651e0339f0e917cef70d2fe5deea800
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/socket-cli@sha256:a7287c2ee884a94c633be067e93d2faa4b058c4b76379cff39021c6f9507c6aa
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/socket-cli@sha256:685430d085578422289e7d4120c3675c9e9c71c9fb94f15f9e2713baa89a18c6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/socket-cli@sha256:205b051739af84a3588f403ee1cc6b7bd2f32a6165c3967fd2f4ff7969230b8b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/socket-cli@sha256:9eb16408ce710b63989f1024f4a80819b8c9b20c4eb73ac11cb8e89a65135b45
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/socket-cli@sha256:9a99198abe6941bd24fa3ea8fbbca0b9eb1f2aaaf47e4fc0f3dbaf45525f4bcf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/socket-cli@sha256:79d79d706d4f622eb380cd78768dd2cbeae9a04b65eec3e5f94fb35d001e6836
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/socket-cli@sha256:97d06cd3c86eca9087d687fd29055cf3aa6196b42bdd4f7f4f00b6ac15bbea07
SPDX SBOMhttps://spdx.dev/Documentdhi.io/socket-cli@sha256:cf42d366f28dceeced17c78b03fbed99db46de57c0983c5757815a4e06d963cb