Sign inSign up
regctl

dhi.io/regctl

regctl 0.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

0-alpine3.23-fips, 0.11-alpine3.23-fips, 0.11.6-alpine3.23-fips

Index digest:

sha256:29800b70699e9970699a7421d1f79223417b186cf9587a429e00fd073dd52be9

Manifest digest:

sha256:050641ea19686416d6fd3e82d7cde8c8804d7ea92ec08466fd87830643e601f6

Size

8.08 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/regctl:0-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/regctl:0-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/regctl@sha256:f5e4d03c4c7a66c80e7edde17c851e43024a04f1ec2c4a9d4bcaf1416f6c072a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/regctl@sha256:525d454192c1915ce7cf8c7271128bcc4bab20c056ecd033fdd528b79dbb5333
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/regctl@sha256:3b8001e0202918035fd11025837ebd0fdfd93f0fd87886f921c9750a5d419154
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/regctl@sha256:9d06b5ef3af006f54f23beda5439e4397671bb4301e4aa711e65530e67954145
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/regctl@sha256:fe628a4f0b8d47bd2d953e9edc26fad3ed70f3bbad66e3a318bf3c9ab733e901
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/regctl@sha256:d9fbbd79b54eb7a5091d2896d60b6a5367e5a483de4116782673ebbd7f0631a6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/regctl@sha256:8cbd2b503c23b403ea53a5e4771bd3c67cafdb3156187430384dedda6f2a74ad
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/regctl@sha256:c69ed2ca172b4ed9eb0c690c0937f00bd29d323510409d7a42e68b98babe8198
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/regctl@sha256:ef7f89c91cc7efd1662df391b18133f08a3cd8e01025b50333c35b542571f388
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/regctl@sha256:7993dd58d3c1036e0402c30f4ca46c7ae839a45bc8bf3e05e7b6939844bb32ea
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/regctl@sha256:cea0986bc0c27d8915ae2f92f8d7b88d6fce05f3a6b359cb177fa739501a7168
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/regctl@sha256:4ebf1263e2be3fa7d89b3310b2706b0d7115d62f1573e9f6b0ac2c47c3e54fb2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/regctl@sha256:80351b9d29731fc7340e1d08d5bc6f73d12d762ab322915df4d01f2bd5d7c3dd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/regctl@sha256:10a018629b48af1c86d703b6f58b000e7ceafee6fbb106f8b3b23ec283a96570
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/regctl@sha256:a250eb872c3ec8541fffeceea5e9efa523ab57b14248cb9e4a7a30e4871f112b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/regctl@sha256:dc75ebf88f744a908db22885eb248d291346f1486fc5e83977353fbf2890f090