Sign inSign up
Socket CLI

dhi.io/socket-cli

Socket CLI 1.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips, 1-alpine3.24-fips, 1.4-alpine-fips, 1.4-alpine3.24-fips, 1.4.2-alpine-fips, 1.4.2-alpine3.24-fips

Index digest:

sha256:ff05ab338ca644693797efe209d32189ab4dbe3b40a065f38e3a52e6af835b47

Manifest digest:

sha256:45849e873bc2d32b53412997372473d77baa3727041b655fb34545b1b6c80bed

Size

44.80 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/socket-cli:1-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/socket-cli:1-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/socket-cli@sha256:eaf101e35beeac1f57f0e126eaf83fd47f6c34e0f744e66cb4a672b0e300888b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/socket-cli@sha256:03c0ad22984922f9512b6eb3f539fda8a766cf158bc51d15d4893bbd3a1fae87
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/socket-cli@sha256:21f59688eaa08423bd6c4dc9f4ff7d16cb2d2c59d3ee931cf95bd6169d635b5d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/socket-cli@sha256:8ee1839a1aad685121ab498c8475396db0f7c9b66ef60478230c12e6c730734b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/socket-cli@sha256:60ff06a814781c4af88cea6987de4314d10c0b7b0ca72543f09bd7eed14813d7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/socket-cli@sha256:b58ac61923aceebfd7647f27a5a98fa3954811e058fbb710358085854cdb2ae5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/socket-cli@sha256:55ccf93f1e98dee533cd41ff449d6e82f6a0af395344357c3da32bf608cf7170
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/socket-cli@sha256:ecba38955baef22ec387ec9acd271ff070dbc5bdd93c72945e0910f365bd45d5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/socket-cli@sha256:daceb76890cd6e74177d5b168ee2a2239ea506c45afacd128e88f1f5eddf758a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/socket-cli@sha256:b68b82cc89911a4278645b368e290ed4b43e55e1c4146d482e467f01b5975dca
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/socket-cli@sha256:2a3a06ea28b2f661fa5e57ebd380bad14802d21b256172f52834b6a064fd6d0c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/socket-cli@sha256:35e27c7e04448f5607573b319b3cf5d40b20843fc3558dc3ed49256583b2dfaf
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/socket-cli@sha256:0ef9ef8ddc2653f7671249e085a6f46fab9d42a4d889a0581f83106dfcf5cf93
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/socket-cli@sha256:804c26819b4add1243ad3eff93d4cb3a358b1264d90be5f31e7d9856612bc8ff
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/socket-cli@sha256:9e467a4b9773b367190a1adeaf134b38547830524e2d8281c02acc63905402ce
SPDX SBOMhttps://spdx.dev/Documentdhi.io/socket-cli@sha256:4548313371464f134396167f3e8ff2b14550fbbc54bab6c139e1b8d34081f20e