Sign inSign up
regctl

dhi.io/regctl

regctl 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips-dev, 0-debian13-fips-dev, 0-fips-dev, 0.11-debian-fips-dev, 0.11-debian13-fips-dev, 0.11-fips-dev, 0.11.6-debian-fips-dev, 0.11.6-debian13-fips-dev, 0.11.6-fips-dev

Index digest:

sha256:e973bb7eeb66856145b139c20f335258a8608566574cf369e9ed5ced70b2cf72

Manifest digest:

sha256:0fbcc4fe6faa3d9718ddd540afb22c9843893b4ff3ceb446952832d2a903303f

Size

32.36 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/regctl:0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/regctl:0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/regctl@sha256:87d36b4c94906120c805b5665d8fbe9086692703b15b66598738f75d82a23479
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/regctl@sha256:b7f1aa30e51c1d2745750963cb032f9b83db0a4741efc460a0c92f50aba4e67d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/regctl@sha256:056cf4f05e4e2ea24c7bcaaf7449fb586e020089a5b0623c4181331fd3aa55e0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/regctl@sha256:0b02397ac89a56b58f2afa28389181e94778c17ec119ddcf425df309489cab31
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/regctl@sha256:ea2f7789cba1d8b5b522db2aa2a44d6fdc2c220a1abec8e1f84de96ad8892bdc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/regctl@sha256:0f1bbd189c576af9e39012eef0f481af946c980ecdae1205ef710946952747fd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/regctl@sha256:596c72877b9c72a460db9354b6f31ee61f2a37830092b73b107c70947a41d71e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/regctl@sha256:405e10c431f0c00e855ca0bb55ee85188d229293722760908386897d0b6af61e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/regctl@sha256:bec06085bb5ba63a3155b0704a984efd11310876b28c70813421560cd1fec678
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/regctl@sha256:d482085572922a81957a21169404f6dd8fa370b2fcf04a4238f4b30edd9887fc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/regctl@sha256:7c3d2180fafda8f1a5a46bd2c632de87d50c006a935dd52392bd82c010c035c8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/regctl@sha256:f63fcfeeb2dbe06094f3c1651f5c9145069700333809e9903b98d6d7fab1f529
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/regctl@sha256:f1e1d637ba0f08611e8a30cf7ad2c3ccccfd01bc60023e12237c2c98d24d92f2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/regctl@sha256:a6cf444c1200af94972510c8d9f3596aa615cd5b73688c200a8e94fed5f9d573
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/regctl@sha256:7b1c442f1edbb2eac3ce1ab6229bb98adf4e0430bab16ed44294d776b1e9561c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/regctl@sha256:7a6e8f4666fcca7b18c08df1e847cabf41756517012e3bd136c4ceff48d46780
SPDX SBOMhttps://spdx.dev/Documentdhi.io/regctl@sha256:7376c641171a38dba866a75dedef2bcf49230422e7fe56a1549792c3a27f245e