Sign inSign up
Socket CLI

dhi.io/socket-cli

Socket CLI 1.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips, 1-alpine3.24-fips, 1.1-alpine-fips, 1.1-alpine3.24-fips, 1.1.171-alpine-fips, 1.1.171-alpine3.24-fips

Index digest:

sha256:c71500e14227fbdce1d1235c57637e082b828d367a280f4b0f1e5190dfa842c7

Manifest digest:

sha256:2591df10556eb1f8f7cdf458705b18fc5059680c6fdc9e49c33a64bc644188da

Size

44.78 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/socket-cli:1-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/socket-cli:1-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/socket-cli@sha256:9ec316a4eea4542b9bf3e5228d9be91d124f036e4aa4818c46a2fd2d3e7e08a5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/socket-cli@sha256:5b1133fa0fc501f9a97be9e7e1a01105f2378710570a2396b0791b10b3e1be73
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/socket-cli@sha256:904f08080c200dfd0dc78d2b5ccd89c023b7ac9e59da5f32cef18ab6dd6c033e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/socket-cli@sha256:ce221e45caef8e197d220d003a29863fcbeac806ee92cfff8d7e7866e3bf4951
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/socket-cli@sha256:3f3b2325c7df4a5cd7c25bed0a15037bb3621df219b8f286c50796e59d771184
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/socket-cli@sha256:28273cd470a86197e7ef87e9c12c367dff183520e82fb0224aa4390b6eb1c00e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/socket-cli@sha256:e44bbd54658cd166781e8677a2005be54ebf82b38b081fa8b02425ca1ba7fd37
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/socket-cli@sha256:acf6f178a8cc22ba6252c5ea6053e2879e6f25c56db60e46128cef52b8076355
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/socket-cli@sha256:dd3ad001ccdf45e65281f9008f65665454eb35acfdc9c6e73e0b468a5a711158
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/socket-cli@sha256:f026acaeb9c9cdf810e395331e529e6263591306158600f6fc67445454d420eb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/socket-cli@sha256:e9bef27fd3c88afeab7bb83e8406cdbba0219691836816744891d70b67fbdcf3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/socket-cli@sha256:cd447d7f709ea133f51f7dbb15926300a1540c1a211789b7b4ffe334185f6569
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/socket-cli@sha256:2fc1a835b0b75050c5c4ea3d0248107ce8ee77392290aea5887bd1f4eea6296d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/socket-cli@sha256:e041f2ae5b0c13a8b8c3021765962a72c18b588127838d1ed3174b540e141859
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/socket-cli@sha256:12e42b5d1133809c80dc256080723c3c91cbcdec616a5de53876095b9be5e317
SPDX SBOMhttps://spdx.dev/Documentdhi.io/socket-cli@sha256:dc048761114a0f65553e2f0ed759a221c819106e4313fcb0143976c874a69b03