Sign inSign up
Socket CLI

dhi.io/socket-cli

Socket CLI 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.2-debian-fips, 1.2-debian13-fips, 1.2-fips, 1.2.0-debian-fips, 1.2.0-debian13-fips, 1.2.0-fips

Index digest:

sha256:b2d0d9f55711fc295a2b2cf7723d1e223d9e5a4d0eef873d4c81371fd8e4dcf2

Manifest digest:

sha256:b02d2a58fc11ee2a4082df4e2c95dddb0ca0284b448c22048d2c82d480534a51

Size

47.11 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/socket-cli:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/socket-cli:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/socket-cli@sha256:c81a0fc2aff7488ef9d9f30c1e3f931a92aca581e0a2de2fcd55e8820489497d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/socket-cli@sha256:9ecf7db4edbb02e61844e4f2891d2c4a6bcce01cc2e6bbeb6756e355b0a26a6c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/socket-cli@sha256:c4d3d18ad4409ded7d4b8a0de873a91f66c22d2de6981c2be591871125353a0b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/socket-cli@sha256:11393559ce376e38fb53006d95d716d57dd056374ad5f2ca6d382e1da61204c7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/socket-cli@sha256:ee8e8d6d1770cf7386b58d1a573a94aad31fe6732daf816ab2fadb8e209749fd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/socket-cli@sha256:5e4296990c6c22031a39d9a8821baa3a0c210059a64ea7f65602933dd424af18
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/socket-cli@sha256:46618e397369ddbaa0a917f7109ea879b8e7b2db3a6b253299340193a6ca18b4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/socket-cli@sha256:79193fb7369fc37e385e057e820e5c7684bd78fdfb98bb0484e0912e635c3b08
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/socket-cli@sha256:2b9d33dca9b7412570a4d2efbc0b572de90ad370e1b759f5793584b2be349fa4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/socket-cli@sha256:f737ae2d43c7e3d496a5e6fc7f44f78c5ded373d1124b4b827a01f0db661eaf4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/socket-cli@sha256:187429c899a96033c86f99982084d5e39df0ba4cadff5626a108480b193b5fe5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/socket-cli@sha256:6db1aebf2e5700767f2279144a5f72411af1ad69837793143a8584007468f033
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/socket-cli@sha256:ceb433e89aca205a595fd931fa3d368bc29b5caa37cffa20ac4ac6872a67daaa
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/socket-cli@sha256:510fcfe9161dd697c25475c9714d869a00960abd188420f97461d3035fc9b738
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/socket-cli@sha256:d15711c16f1c17aea9080b5c31637fbf012f898d9f92b63b27534eb7a3438682
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/socket-cli@sha256:ee3fe54e172158ebe5077dad19cdef003b6a53e0cb214e12e643818729816718
SPDX SBOMhttps://spdx.dev/Documentdhi.io/socket-cli@sha256:796df4b3a76962cd78263aab06293b052bf595c9addb2066d202804cb83e97b7