dhi.io/socket-cli
1-alpine-fips, 1-alpine3.24-fips, 1.1-alpine-fips, 1.1-alpine3.24-fips, 1.1.173-alpine-fips, 1.1.173-alpine3.24-fips
sha256:1ce969e15993f56fe0133540f189e9a3e4105d82a7da15f332eef7cccc791b7c
Manifest digest:sha256:ba1b73630fe7da945776797eb1c5628b4e84ad5d9f877000c07bbddaa22a1b06
Size
44.78 MB
Last pushed
9 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/socket-cli:1-alpine-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/socket-cli:1-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/socket-cli@sha256:b69e66ae8cfc0628bbe58c23130a9cf9451153ee9473dacf6595860c96e115c2 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/socket-cli@sha256:fe813a44944ac62f0203a729fb22d4d5df10dc9555bdd192823a637e6095787b |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/socket-cli@sha256:85849f8b4b7de5867b64b73c996b8cc3f66cbdc670798b4cce4ea677af4895e0 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/socket-cli@sha256:92340bd93055205b8e047e39bb753dee15c63f81a7fd55a48a49177d52275638 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/socket-cli@sha256:00f498bdde173e34f9b39dc5f21ae02cbc134e04d4faa30edbbc01c5c4f32962 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/socket-cli@sha256:a58b39322f5ff6f1e08a21dee1b2af7e005c5fd2dbe0f70a585b0f4467fa2ec1 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/socket-cli@sha256:cfd0c6c1d573cd8c0fbd8434159dbf4cb8461f2c74c7577bad27de39e0c0d282 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/socket-cli@sha256:e3d8b731544f617fa3ac1e30db8d385cb9645287108826b768ae6937ff7458e5 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/socket-cli@sha256:f2d63c7d6f5b0a9b6721512ec8c0dd728d8f9c076dfad76c78e0940f39c55e17 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/socket-cli@sha256:b0bb40db1662c604deb402a60e444c8e16962cfce918ab514ab533b540cb3b5a |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/socket-cli@sha256:1caf18b3cfe7c905ad8f247ea7339710612e8300ab68d8071828f43445224ffd |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/socket-cli@sha256:85727e79cb92e101cd3441181fe64c2a62f77423819b14e2757063c7706de1fa |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/socket-cli@sha256:11e962e5752f71272d963e64d087882a0829e3036b3acf783600e0f0436229d6 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/socket-cli@sha256:939ec361aa0d75756a842c7c3ec8be209dd6e3d07ba25fd8e5a4f175c057bdde |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/socket-cli@sha256:0aff1d9a6cd32b6d70319ba5589cf889fbe975e0339f351fec070814b2051bd9 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/socket-cli@sha256:39bc6c9a2eabb1bb6772fc96802f68d78f8c01e34ad5883f0a8b4642a02a675d |