regctl

dhi.io/regctl

regctl 0.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

0-alpine3.23-fips, 0.11-alpine3.23-fips, 0.11.5-alpine3.23-fips

Index digest:

sha256:84036055642d52b2e7f457fe6ee2079f7c22edcf82392bb0132a63d00a38837e

Manifest digest:

sha256:19da70f435f9b57d7440529d29047a563c735be8ed525621c477139ab7bca684

Size

8.08 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/regctl:0-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/regctl:0-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/regctl@sha256:2a05941cac9113f1b3d3c675847c8764208315e6edb8760f1c5f91dda5f9a4b3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/regctl@sha256:826cfa16f13d32e1912893d5b3a43093d20022c1b7b24330bfd336a98415ccac
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/regctl@sha256:5bb47715d7c2f4a0a724cdb24d496126c9a052dd53368d0234806651a5e95246
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/regctl@sha256:397f90619fd390c9753b08b74a26f18c136dc57a860ada2c790c166ffc987a14
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/regctl@sha256:c49946c25730d7ceb850d425d3a4971863ba990de4150dd08457d98336bc71c4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/regctl@sha256:8559e5602f03961b53c3bd734a3e239167dcdf673591af2de38bd7a38c5b157e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/regctl@sha256:9d774f772929c25bcf3d938c1eaf846383187bc08a06cc06d1f1d6e81b66fc6d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/regctl@sha256:122282162fa51a0b0ab5b8bdcc16b227220f26d98cb4bed1dbc2c005ba898fae
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/regctl@sha256:7dd95023e763ab453099b918a36bef4b3d9889062780d68b880637aa440de67b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/regctl@sha256:96057fd8aa73bf3046b2d6b89ebf127109a32798a66609a5cf98e0d858639bfc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/regctl@sha256:a66dcbc62dba9ebe2e348593d89823526ceff685962d41e979e779b980b31071
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/regctl@sha256:d37d45d0252b3b76911968a1227a84cb3bfdc75fa913d0154089fa3b492a493b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/regctl@sha256:b640a18451da2d745b7743f9786e70f1d8dd057b00a9fd82f3433133f74d0f86
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/regctl@sha256:5a6fb088c837bd929450ce587a38426a4c4183ab1f0da0b9de724fb0a9edbeb7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/regctl@sha256:b189aded24f28e5dc385462f8040a023d63b3977182dc36f782334e556918792
SPDX SBOMhttps://spdx.dev/Documentdhi.io/regctl@sha256:193b2d7125b983b5654c5f4a3731a568f317b00c70b281603f94a9524848a5ad