Sign inSign up
Socket CLI

dhi.io/socket-cli

Socket CLI 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.1-debian-dev, 1.1-debian13-dev, 1.1-dev, 1.1.176-debian-dev, 1.1.176-debian13-dev, 1.1.176-dev

Index digest:

sha256:daa0fbf2f0643db91121af8d6b3d50582a2e3024612f6d2002f913659dbebf67

Manifest digest:

sha256:6c2d62a7a3b58c8272276e8f69c74c7dedbaa733c0150a1a6d119bf4bd926a02

Size

83.62 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/socket-cli:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/socket-cli:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/socket-cli@sha256:a4ab962c8c32ab5a9dd3731da3103f0aec8f1e181abbac80eb6b4226253c6233
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/socket-cli@sha256:186054b62cdc1f190c1b38a5f27e5df2c0c881f26f0b997de565e9224f1f1ec6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/socket-cli@sha256:e53e20f21cd679c2e59f1f101d40b43c8aec287ce80a5926a061b455b35f4c32
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/socket-cli@sha256:81881303d90a06495837dba09a4c597bfbfbb4b95e48d2ce6992de67e91327ed
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/socket-cli@sha256:edebbb9b2cddf1ab414f1ce90878011701fc37a3e22690d767327d12a73813bd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/socket-cli@sha256:84d1863ca8bd2701deb393c658465c3cde933fe330cd0e43518d48ef9e1ac28f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/socket-cli@sha256:d84c7f4c39a8c8acea78e4c5e41e69167aa50577e96873340734aa939e6542bc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/socket-cli@sha256:fe7563a5a05f50d2fa804706b5de75e0d137036370bf22d5fd947246257fbbb0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/socket-cli@sha256:2969f1dd69008e9f9badfb4b657429c754824d2e965cbc5087b6b7bd765815c2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/socket-cli@sha256:2dd25283f0a7c02fdd8dfb3fa48851c791f9edd3de913dd5fac5864b47ff0124
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/socket-cli@sha256:2a40a94c0d8b916f9964831645855f94cdf3d3dce48b263b292ac806b8c176a8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/socket-cli@sha256:21dc14c25443628e987e36ded23f3141399186accbf50545faf6180bf274a12c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/socket-cli@sha256:bcf5497054916f13ee30f6219fde39290844852ddf00ca284dd7f0c8bb71e6de
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/socket-cli@sha256:81687f1ab70a73880a7bcdd4f22c3294118e118296d5b8421cc49e7218af7491
SPDX SBOMhttps://spdx.dev/Documentdhi.io/socket-cli@sha256:3590d5ebb38d72b213d964cdb4f92528d49885a982c81f056fed7595fdd8b590