regctl

dhi.io/regctl

regctl 0.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

0-alpine-fips, 0-alpine3.24-fips, 0.11-alpine-fips, 0.11-alpine3.24-fips, 0.11.5-alpine-fips, 0.11.5-alpine3.24-fips

Index digest:

sha256:6b9acb98e6bb29382593193d43c4850b2ccd4bb56dd1e8799dde8305873e7d0e

Manifest digest:

sha256:99b597e00037cc4d31bf4436900ee06b9b31e3d6eb9d5ae13c1e14fcb5c97c6b

Size

8.08 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/regctl:0-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/regctl:0-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/regctl@sha256:17b4629e1a2c5eee37b3811481607d71285b284e5b3f11bbf54849632e08e195
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/regctl@sha256:1258847839944ced76eb405dff785f22847bd2ee7ca54f03d701400f1a5679c2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/regctl@sha256:715a898d55bd5c4b0e40c1217c8727307125840c7d677fbd17f5aa1f1e573267
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/regctl@sha256:8ae62698618a696db4f55fa76420e6e494b039efb6f1fd3656809dd5a1eff85b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/regctl@sha256:7184c3ce0a3d5d4d29d674649e7de45a23487a1d8943b0eee9968eb1e5b26f9e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/regctl@sha256:bb05e627b0ceeda98db25f288d9dfa0a5b09804a7dd053d1733af671174459ab
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/regctl@sha256:30a945890f51d0815b738418233e5f94fed423b0e52e81f10bc47853a50061ea
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/regctl@sha256:7444a26bfd61bd4a1a7607e6236fad9ac3d566ecfe4bfd8944100c98fbb66a1d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/regctl@sha256:72d61a447ba74c95f715fbfa17849bcc9d32134f92505de701e8fea2f15bd3bf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/regctl@sha256:6e5f0e926f504e7aa879e3898772806b3d85f6b70930013e8de124103288ba3e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/regctl@sha256:f717af8bed4c0dc88aa614aebaadd389f57a951329d3a86ea7abfab19a342183
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/regctl@sha256:97d60b60eca0b680f9adaf55186cf14fdc8bc539d9fdadaa1d2c8186b4ca6d3b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/regctl@sha256:f3a678541fde4a6cc4f0823da90202e2de1e868a2473fbb364d1c23ffb48b667
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/regctl@sha256:a92757cfd17e437e66041c6e15903e64ab4bb2d547f75cb6e9ecea75a2ee9d57
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/regctl@sha256:d8efa5304542ce3fd9dc8866baeba929ceb58c364a00013172ff56a197a438a3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/regctl@sha256:290dc56c1fa3233b2b4144d32ad189fa052b52e76b8881c3ed6eeb2662f075f0