Sign inSign up
Socket CLI

dhi.io/socket-cli

Socket CLI 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips-dev, 1-alpine3.24-fips-dev, 1.1-alpine-fips-dev, 1.1-alpine3.24-fips-dev, 1.1.171-alpine-fips-dev, 1.1.171-alpine3.24-fips-dev

Index digest:

sha256:98346e91f10dd044dd5669491fae7106abb660bbc77b826950becd45936b2e17

Manifest digest:

sha256:a7a76af5ce8837d4e4b3a360317e6106d6efec78a17d758488302c58067b2509

Size

52.30 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/socket-cli:1-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/socket-cli:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/socket-cli@sha256:dfc193561ef20c149b6e499a56c769765e1b0c0ad7a1ab88626127d0616a5593
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/socket-cli@sha256:730b1a1324357ffd8ec1025df999feb59e5b576a494e9381928a8b4206ddaadf
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/socket-cli@sha256:ae0e3bd7e46e1deb58fd7e7acc0033bfada51847e555f373e0f3bb5738504cdb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/socket-cli@sha256:9035edc20b8b420567cc69f376e9daa116d76bef9a25a06963100764b312ca47
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/socket-cli@sha256:a7f736ebc4128649df8a07d85ce6c0cb8a110a32d0d94f405a79ad8a3425f543
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/socket-cli@sha256:aaff54a3052d9115d13395fc4b3a7b81ac2c80b19d0b3c4988c9619209937b3d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/socket-cli@sha256:37b08faf926303b4de7bd5a4b5fbb3e66cf6def5d56a6f96171d5bad5abe75e8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/socket-cli@sha256:2809f23ec87076c28fe167d3d945bcb075f47cf6a8036e4f623f55d7986bff7b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/socket-cli@sha256:d279252c0ab773e24d50396f9784022fecca74b46340afdccda74995e17e6f17
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/socket-cli@sha256:72ba9646b4792680503f34f879ba56aad1ef922908c7490f35d98655d641e4c9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/socket-cli@sha256:5d01595d7289f6774f31b354212ba705b2037f56a1322179a72053320ec744d0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/socket-cli@sha256:750133d9aa0a65e8ca96dd390239a7b5747a1bbddd79d8373eaf5902b9307b4a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/socket-cli@sha256:15caee3edcf66013536975e4907897f50ca3c64b39a1e05aa2e6d871aa0740b3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/socket-cli@sha256:5fc39f3ad978d76894fe27eb9cb37d794f280322d6a489f4ec984f4d5b84f3a3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/socket-cli@sha256:47ac502b88baf3e78bfb06e5329e2097611452dc9b21f0af097076a003590b5b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/socket-cli@sha256:fbcb63a7309191195c933e43cfb8baa8d9c85a9ca9d34b88d61cadf12e589455