Sign inSign up
Socket CLI

dhi.io/socket-cli

Socket CLI 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.7-debian-fips, 1.7-debian13-fips, 1.7-fips, 1.7.0-debian-fips, 1.7.0-debian13-fips, 1.7.0-fips

Index digest:

sha256:25d14be1f5b431761a8127d1fefc0af8afc05bbb9e519b5248037b297bc8bc85

Manifest digest:

sha256:c810d77c803190ca6bb673c418736e452f223f0e64bfb728ea6617a8e7881e77

Size

47.13 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/socket-cli:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/socket-cli:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/socket-cli@sha256:003b17cdb4742ee9931f570c01dd91fb52356df20d525a4ba327a735bcccb6f1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/socket-cli@sha256:698c22c8851fc3346473964a54448597422b46ef2773d00856451dd37e401ac1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/socket-cli@sha256:7faf63a21872f9a7cae9ca3cf7f8a32f014163bee373e82b289a0aeae677d815
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/socket-cli@sha256:feb9964d670e4f1b73ff9eb49e02438f63022c03c58f756ecdc67098c2bea409
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/socket-cli@sha256:d9426f2193281c999be7acb61e6e9440c885feeb706bd40521e708d2e5e318eb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/socket-cli@sha256:cadd6a44bb64e1caecd4d5010e121a532d70cd0e8a5ba647943529814be190c2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/socket-cli@sha256:6f42f978b06a170816c317ef156021d45334f05a1002f45f1c507fd2bc4670f2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/socket-cli@sha256:107e65c8a82ba0750123e78e4478a762dea2b90511d3c9c6b70cb584c061de77
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/socket-cli@sha256:8dcd25b5dafe6b9c5e4a9c3e156b1d2c4b148c23113354174737d951b726811c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/socket-cli@sha256:3c98540040a4b0797fc3f749bcfde2c040b7ce23f8b6edfe6f71c9af9e8c4277
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/socket-cli@sha256:bd876642835eb07b4ce1524b768cdf414b0aa85976b6cdc90124a10b7a02d3ad
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/socket-cli@sha256:a92b8f372c7e3c791fb2933195e90a04432ddf3c95444ff5c046402c470b83a7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/socket-cli@sha256:25a1879c0971c510816b9cd9095624b3eb1b5367d14329cb8a7ad47c51755827
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/socket-cli@sha256:0c40dc41a774bfb6004e66b670c5fc1378ead0d40017cfec2aeb864bbd95599d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/socket-cli@sha256:020ee965c20a1cd52e42c207a80b74926cb5c811558893f780bffeac7464a39e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/socket-cli@sha256:4b4994bf33822210bd52b497006cf54b3fbc5450988bd280e41520dd5be8384a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/socket-cli@sha256:052d4e588445477ab24bc2aff6d9e01ec2cebd961c7b894d5a7898f076043021