Sign inSign up
regctl

dhi.io/regctl

regctl 0.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips, 0-debian13-fips, 0-fips, 0.11-debian-fips, 0.11-debian13-fips, 0.11-fips, 0.11.6-debian-fips, 0.11.6-debian13-fips, 0.11.6-fips

Index digest:

sha256:0204f267993882c259830ff3b13788f26d7ed1991ec2883ade4d8e0b637a2047

Manifest digest:

sha256:77300660b593da6605d481740e8a70859c5ce5a6bed0f14b3dfc5f19970dd56a

Size

13.17 MB

Last pushed

6 days ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/regctl:0-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/regctl:0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/regctl@sha256:ca0268f2990d2abf4c8694d950ff2ad8ff99f9fb04677ee0aab88147331ec0d8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/regctl@sha256:1638a29b24dda3ac06f380f15a88e4bb03e6839144e7ae543ead28211fdc3fd8
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/regctl@sha256:e3eba9c7f1081d2a75ade66c35810e179032f830ca55999768db69241033b111
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/regctl@sha256:3662530d4accdf9898e5c310d4502802c66b3b5e79faf52c16ac8c405234aa19
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/regctl@sha256:cc45c88a9d602980c93a6f0edf29dc224bd1e94af9ae972377d4a9bbfe4f3e0e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/regctl@sha256:369f5376c512c399d645b56cd767b86e77c6b2b0f49ec65c8c4387b1d71fe326
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/regctl@sha256:28d52a81bbb46dfaf9d38435cc6cd9ea31bcba44c361fd67cf63f07fc50efbc0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/regctl@sha256:1c3ae6b800b09be409ce72a7ec4fffaf456663655ab937e462a83bb52dfc4fb7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/regctl@sha256:0adfa66d60b777f1da75904153fdb8e52436fa20d4ba6f1868872d2630394f6a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/regctl@sha256:f6c5ee7224d496d74fd55a9e0a0f6d8dfbd9f907161bbd9caa0f883b59337cc2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/regctl@sha256:20750f74d83a450eda67760a66aecbb403671adae9c36f6d4fe85a398c4e57f7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/regctl@sha256:878591cb41a362bb4cb2bacb54d0d8e8fc3a5e85cf04d22a7adeb21f1a284e1d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/regctl@sha256:5cf7d4c3ab6dc106844689fcb31a9a66fe22668790d52c4b8f4b470d8514cc97
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/regctl@sha256:48eff0f7c0548e681c3e02a979371ff9573e8928d95d229686eb156bd7c22568
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/regctl@sha256:30c710fcca4572c0ab85db90cf6f1b99d10820b4ebe4bf10720dff993da9fec7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/regctl@sha256:cf745988952b2759d6e2c65a49eaf5fdb3a9e6e2f9c552533d0ccd6826912320
SPDX SBOMhttps://spdx.dev/Documentdhi.io/regctl@sha256:6d3d4863918db0609eda58e1f2dddf4fb01b0108fb6e12d3e544ddbbf03c46fd