Sign inSign up
Socket CLI

dhi.io/socket-cli

Socket CLI 1.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips, 1-alpine3.24-fips, 1.2-alpine-fips, 1.2-alpine3.24-fips, 1.2.0-alpine-fips, 1.2.0-alpine3.24-fips

Index digest:

sha256:ccc2a55dd3f9a0ecc1e2e9647c85dacca288e7b9628315b40c1d4f65672c1612

Manifest digest:

sha256:6bf1190adaf9ce84ba2ff8acd5b8486009466400f3c559fa2b0c0efa48cf2406

Size

44.78 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/socket-cli:1-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/socket-cli:1-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/socket-cli@sha256:4b468f191b49b9dfa5a27c81447bdebe24d41a45d436f03d6a7b0af652f58dee
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/socket-cli@sha256:d573c2b7e06780027ece7fccdac444f3c680ea7d5bfc764a487372019f01c85c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/socket-cli@sha256:1713c2bd6247e6a14e71b8ba0b774708eb59650f7d0fa35b924fc87432a9279a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/socket-cli@sha256:668b9120b4b0094b80c1e066a12f33305833b6dcf3345e0547d299872d4de9e4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/socket-cli@sha256:10256c4bee85347e50db04e76b5f1bbc047857253841602302c814bd27542aea
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/socket-cli@sha256:c28019ad07c8ada9d624f69a53da14c3b20d9c847ae7a9ec095eb85b17b7f137
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/socket-cli@sha256:82b87a7a1657e31c89834afa8694f350ec7d09d84727a2df84a57660ca0c80b1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/socket-cli@sha256:2c4e4e34c5d028787ea0cd8fe2e41db60245af7c2a68f6a043a59948edc66c97
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/socket-cli@sha256:b72be846a1017bb60279fb1f9d6f322b9d580a996e2cc0e116a40ad2663bca3e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/socket-cli@sha256:03f78aab7cde1ea6b939ca657938d4dc5105b99844c6455afa6494d0b3c2c03c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/socket-cli@sha256:047168932e69afcf17ac84a633f21a2aedfbb07482ab2a21562dc88d7680be53
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/socket-cli@sha256:4c38c93b774cd4976a6579240a5a2abf26c00f69fb875095a10cbdb3bdcbec91
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/socket-cli@sha256:094051e92c5ddcef12bf2e23f4156d1bb594113dc5bdcf7078b52a9cf03cfe32
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/socket-cli@sha256:e7f1037c979194a455f761b4607fcdf8870a66b31aa8552cafaa392b97cb3a7a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/socket-cli@sha256:fdc9d55246227d1adf98651884ca20c74828f749d73a50dbce1f801ebb526a19
SPDX SBOMhttps://spdx.dev/Documentdhi.io/socket-cli@sha256:eadf4b6b57dd27791eabdf962ff5aa6deca54a9dde27c59a5841a3dec272fc63