regctl

dhi.io/regctl

regctl 0.x

CIS
linux/amd64
alpine 3.23
Tags:

0-alpine3.23, 0.11-alpine3.23, 0.11.5-alpine3.23

Index digest:

sha256:0c1c4e7dc062dfa52ddf4bc81ded024b28b617b9e43707f5a3bbf0243a5b5299

Manifest digest:

sha256:8fca8257e677e377323bd4248ee1224bee639392627aa810776991418b4fed76

Size

4.69 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/regctl:0-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/regctl:0-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/regctl@sha256:1ffe8f045118ee65f636ef1003eaaa35551494032e60f1983f11227d995b93c3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/regctl@sha256:05ba1c03a287417214b14be21566fac2c5f9cd25c022e84293c37c718319eb9a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/regctl@sha256:9483370ecaa3e564bc413789d405d6b46aa430896ec600c3b9f2be3c09662a4f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/regctl@sha256:cc170031bff3fa38dd9319cfa28d7d552596650fd7511a3446c483f75e70a1f4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/regctl@sha256:0602a22957618991141507a3d063e5a698179e7f31ec80415c8854ec50dc8ecf
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/regctl@sha256:794670dfd05c0ba31b9f4868bbd3dd27acbceadd13b5bad2d1e59edab266e327
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/regctl@sha256:9ed826fdbaba650573f3c0cd39e8fccfc160fff5fb7ec579a423878e8f8d3372
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/regctl@sha256:de5493c57e6c356b268c6e9cbda299fac1dd95a3f1c1af86d3b72d373146ad59
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/regctl@sha256:6e1a50e2ccf5b5d2ce3fa51427506bb2093f710057ad0a2d52981e261e86c50e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/regctl@sha256:6cb9a40c1364e1f3108e13815c1594e59558e59053eb02d4973d31c6b020f702
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/regctl@sha256:cf9b73106624934aad5c59af0c7723ff187272a81a9ed24a195db201f8631cf0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/regctl@sha256:12664f7bfa8ecca62c349f446b94091d0926af9b3140258d97f5dbe573a7f293
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/regctl@sha256:e6ce0206586be80e5b645344e9b71737e526ead87d3622aafdb3e04b03615797
SPDX SBOMhttps://spdx.dev/Documentdhi.io/regctl@sha256:5adefc37d40f193819ea93c27038d2bd39b05c7147c26f1d1952ebe70b487695