Sign inSign up
Socket CLI

dhi.io/socket-cli

Socket CLI 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips-dev, 1-alpine3.24-fips-dev, 1.1-alpine-fips-dev, 1.1-alpine3.24-fips-dev, 1.1.176-alpine-fips-dev, 1.1.176-alpine3.24-fips-dev

Index digest:

sha256:df952d2b1ccd2028894bc83a1a3c2b62f4452eb07f76fa42895a97f5ed2fae5f

Manifest digest:

sha256:bc43316a32fce93890a1af2fe836357026859646733e5c1e86f1e03766e95007

Size

52.32 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/socket-cli:1-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/socket-cli:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/socket-cli@sha256:8e89e86e1c41d5e951c67b20abacc3a9ae142a4aaadf1a74e49b8ebaa0c18a13
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/socket-cli@sha256:2cd9e54d1f4f78b34fa8c160df43aa0aad7cef7d3c96ce609baf091d129d6d2a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/socket-cli@sha256:92cb8a829e4c6e76573bee85a0660e4b078fadc59cfd13d60f5dae265e4b4f29
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/socket-cli@sha256:81c8167b8409f407cc530597d686adea9e90b2be8276edf8cea016a46edde578
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/socket-cli@sha256:91a557d5904892bc9ccf1d3fcbc30ea4e0548f6a01c2008068fd10c9765f83a3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/socket-cli@sha256:0170162b0ebb2d68ebda65a0ce4cf94937723d191417b1340386bfeb14c7a903
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/socket-cli@sha256:60b9971cd1cf5e04ba3b59d99e5c97972fdbaa80b535eb768e4828eaa7d3483a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/socket-cli@sha256:60421effc549ac99c9b9d1a44dfe1c5a3d6a28dc34640ad6095417de2d9744cc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/socket-cli@sha256:0370238f9edd5a6f925ae6125fe730da76ce1ef49c5ce275f652f4e985c393fe
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/socket-cli@sha256:37e07687dcbf90a7992896e71eb89987b9f01a33f330b56aafd1f3146c6f0d67
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/socket-cli@sha256:61ca96453179c9f7b1783864b89a1e262689126e1682e855c128bae5c25fbfed
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/socket-cli@sha256:ecd94f3770ae876b60b4853fd35ed87c535fa9ebcfcb4804d28cad45bac7423c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/socket-cli@sha256:5eddde56b2120051aeae315ab22e7af5c656428c0c48c6ddd2624058ca461756
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/socket-cli@sha256:fd28271b6c6b2fdeb429d6af60e2c7f27e80fe6b7e72a322bbb3e586526faf47
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/socket-cli@sha256:f3ad255ad0ad6f2d778e1a98cd4fd94207c1a60228745b23c8bffc74d8211d7d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/socket-cli@sha256:df1bf85e91260ab41dbb00430f74c31cfb2ebb42210f0d9bea81680f4a6d12fc