dhi.io/socket-cli
1-alpine-fips, 1-alpine3.24-fips, 1.1-alpine-fips, 1.1-alpine3.24-fips, 1.1.174-alpine-fips, 1.1.174-alpine3.24-fips
sha256:17b0c79d6d9cc97a37fc69d4383d6d233050d9e90592859e19ffd22e0a0eb386
Manifest digest:sha256:24556f95b9177343196daf77aa9575e57ed5060a089028b36d4695d82c41e7f6
Size
44.79 MB
Last pushed
7 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/socket-cli:1-alpine-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/socket-cli:1-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/socket-cli@sha256:ad88383372f211f68a74bf5836e286ba392e721c38f57bd26b4937f311ba410d |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/socket-cli@sha256:9ec74f291b9c1c44bd45d0c20b29b466ab0e7a03b319bb95e0915d45272b285e |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/socket-cli@sha256:e8a02854867e82d59e1c5ecca7ee0b59e64af6f06c1827962643a504544fc6c2 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/socket-cli@sha256:266e957a8a42599a7a808c9237282d2793616c0a8f2e0ba47c089340b8b73a14 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/socket-cli@sha256:91b1fbe835a270d04b2271ae08630913f84a6836af111096ab99b21f315da722 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/socket-cli@sha256:7239de10e1c07fc92aed327f45957e2fb72a57e354d19c9d8f617602b6688184 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/socket-cli@sha256:b57963a21fc0ebaeb583c634c6b6989bdc0973e609ce26e2d482359c5a01e241 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/socket-cli@sha256:33dfbc9406d14be3709e2d0b343c423c317a72986ee91a463e12e31522cd32fa |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/socket-cli@sha256:a733383fbb66cea3c01f7d257fae5b50ade598a630cb50840289a4fef4a4b1bb |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/socket-cli@sha256:ef92789e10a2ed6a0f8ca39fe30d430ae4b91e8b1790f0761954cff7ffb998b8 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/socket-cli@sha256:78c7d8a5783979f0117b0a5208d38b7691a3f7984c1991de17ec69cb014ef5a8 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/socket-cli@sha256:6e7a974fc1360f944f3f0b8f89474af6d3130cb3d87106b295cac5a6527b8e3e |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/socket-cli@sha256:90b034ac1011f079ef205b39ef4b20cd6bc173da09eb587d5269f8e11038e642 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/socket-cli@sha256:db40dcca77aace41e1799c85c4711ec9fb8e68f87ced53b0915150f645d6a2b0 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/socket-cli@sha256:65450af1f3cd7d9106dc70783fe30bc589689a2942687bfdfe046b6455e501a7 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/socket-cli@sha256:755359b209f93488c6e5a6169287056ddcac36db963a8f2eabe0857b1eeac909 |