Sign inSign up
Socket CLI

dhi.io/socket-cli

Socket CLI 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.1-debian-fips, 1.1-debian13-fips, 1.1-fips, 1.1.176-debian-fips, 1.1.176-debian13-fips, 1.1.176-fips

Index digest:

sha256:345743dc7358afff654a679e27b83c9f380e0ecbc2156eeba90596f24a0f74cb

Manifest digest:

sha256:d1cb33188e9f0de3a25eaee6e963996fe88bb8ebd653689e1d6912092e20b3ba

Size

47.11 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/socket-cli:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/socket-cli:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/socket-cli@sha256:63d006272a50ff3a085b172a91f5c9b0dff6d01f8ab93dc162f7c3a40c8625b2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/socket-cli@sha256:31928c5b5605a450041bacf5e870a66f8d21a4b8fe0a03c7db917d6dafec9eb8
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/socket-cli@sha256:4e26d129ff4537bbf198c7af43392b0a0dfd07e1789d72d231e96ee5b794e0a4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/socket-cli@sha256:e196443f68708dfede82ca2a78f919686e67188b59ce8fcfad8222163ff7b180
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/socket-cli@sha256:ff7ea087966ac89bca09ecf8106bad036aa623af94a9a7ba42b8ac6d9355b9ad
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/socket-cli@sha256:867e344f54513eb14e1011be90163b40d476d119289ce62e527cae95df9652c3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/socket-cli@sha256:a98fb76693de99fb6e991e4ab11e4ba73e3c21f5bce73ececb02073d9f5d12a4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/socket-cli@sha256:c90c8efc672a53326d6c8d21a86561e582aed01e4fbbd9b9cb395f07d9a66877
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/socket-cli@sha256:0bd19e914ff74424c80c2494a251957a1587f9fec197a43114befea00821f7cb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/socket-cli@sha256:92971d30a430e7aee8c5ea7e87f98fb749616d9c3beb8329498bacad96026455
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/socket-cli@sha256:114440b3d189b1dc643d68355234f58d213be631e6353f48e90a03e3e948bc92
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/socket-cli@sha256:876521873e0170de5e6d10d9868a02b1062b5e80b6e58f2b9e2159cf49130eb3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/socket-cli@sha256:a2c20f166609bd4fb5fef4ba16d8132818babad57edb28730bb414865735d21f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/socket-cli@sha256:041af6aab9d4cdbdbd92e618815d0ec2c2927c5758797d99812466a74b7fe606
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/socket-cli@sha256:409e2fed136092102aa46003f3007c8ee8b88dcded548b308ebdc521ad62ac54
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/socket-cli@sha256:36da94c136851f14647ffe09ef5cbdb4dc1e57eb4eb277fdbe923a6d04d195d3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/socket-cli@sha256:3834a0df80ae1070d93a41814c9ceed33bb496f899c31a2b680fc3726a7680a0