Sign inSign up
Socket CLI

dhi.io/socket-cli

Socket CLI 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.1-debian-fips, 1.1-debian13-fips, 1.1-fips, 1.1.180-debian-fips, 1.1.180-debian13-fips, 1.1.180-fips

Index digest:

sha256:20c17eaa1fb62b3d9a1828e1bc7ffb7a1afd1a9ea256f12c9a2d912bd6d2f1b0

Manifest digest:

sha256:1eb737a37736cc5e487a3d2e53956d652b576df24e2abf6d8f7419109253e6c7

Size

47.11 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/socket-cli:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/socket-cli:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/socket-cli@sha256:dd8b41fc25f73a0c53780924ccd17e83ff842ceec40066fee9f0ce16079284f7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/socket-cli@sha256:7691544076f8f52b9fe518be648b6c8e2d8639daa0f7f49b0159dfc4382beb4c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/socket-cli@sha256:70d9db6227d3c076f77ca829b7c7cee4f931f3b54fdea2b474890063e1a2da90
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/socket-cli@sha256:4344fd7a2e20921b6702a85f74a2d8d8fd1994d6081af21b025ac2cb295e1318
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/socket-cli@sha256:8e604aa2d9033c5760faef593198c71cd23d12ff2216a02a7ae2dda13cc0b67d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/socket-cli@sha256:eb2b50b602527583c297397a6672cf4518bb29f7c02154fffd2864ba3c0b7c72
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/socket-cli@sha256:e60d20d8f600a20ddf3c7af2bd01a8f97234424c8f8a1ab6407ebe06bb05a7b6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/socket-cli@sha256:4176311ecdbe3178dcaf33c709d56b387a4f2990b8a1a59158cff3e877f069ce
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/socket-cli@sha256:4fb1367f51177db3b08f3c6be84ea5ab3cd016b9ae1e8516094d8b85d1d97ad2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/socket-cli@sha256:11889a1b50e0162e8813006232ddf42e6333ccacef2fdb7285bb339e8d55c841
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/socket-cli@sha256:6d4d63652a9f8060afaefa84551aa9d5c3a5fa80407451a94bc92c6d83bec9e5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/socket-cli@sha256:4943c339a3649fc29faaa810f68b7e588fa64cc69e35ae728737327e4caf6c10
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/socket-cli@sha256:e5f60f2419e9909c759c63d18fefbe4dc05262c444b4e37bbe2aed99da436d00
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/socket-cli@sha256:108c425ba86848804b51d504804fce7852c1411254a67d5da2372850bb63e0df
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/socket-cli@sha256:5ad99a086325e3f4b7f04862b4a93ffc1da1ab5d5e42eff8607a509b5337f99b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/socket-cli@sha256:a599921a3d640e5cf23ce09f06b5c67dc0d25a2362801c692306e34d2506c0e8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/socket-cli@sha256:46160c96ff39de3e69f979a903a835835e512abe163e6896bd9356cfe405871c