Sign inSign up
Socket CLI

dhi.io/socket-cli

Socket CLI 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.1-debian-dev, 1.1-debian13-dev, 1.1-dev, 1.1.178-debian-dev, 1.1.178-debian13-dev, 1.1.178-dev

Index digest:

sha256:60e64b37c8f15ce34da7739ab2a5e4e4a094a09c4b4d3879a8e120dc4dde9481

Manifest digest:

sha256:1bc4f26ed5ae0ec84238ef6b4d269589bd4809902b36d7f6092bf9c818984582

Size

83.62 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/socket-cli:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/socket-cli:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/socket-cli@sha256:b956bd9a1a62acb3bd2402a1a4a45a30c72d7be6afe7851b4646d446f4ab645c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/socket-cli@sha256:d9c2157f23d8698bdb2bf2bca519db48313174050bae64d513bc8aea99c526d8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/socket-cli@sha256:6f6bc982c8e53345fe6e7b0a8515b76295d5313aee84e403f46367003ad4bdc4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/socket-cli@sha256:2de37dc4ffad5572268dec8b957de5456c7bbf1622eda991ed227f5f6aedf898
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/socket-cli@sha256:11374a0f8cc72911fc56a0f9b43560dbb244c62f05c6b0e039067878d301da00
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/socket-cli@sha256:c232987ca650db0801631d78ac230b4043f9ae9ef93ede0861ce4bacfd0c68ac
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/socket-cli@sha256:168324a0d8fe25942a959ae6023620548e6768f7f62ea456f98a7a1aafbcce6b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/socket-cli@sha256:b223bc20be32000776a5eba3edfb5e50ee5fc8706a78f488b9d84dd92e014a87
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/socket-cli@sha256:955e4e57a7eb103046e952a522a812d00dfbbf6cca00fac7ccbba81e2516f2c1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/socket-cli@sha256:59c6bf455da9d1d32fe042334e41de5aa0d0049c9980c8b2232893b3171cdf8f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/socket-cli@sha256:3cf1254e8656c869f9d9edfaa6145215e9f44c1ec0a7187eb3b763c584ae2e32
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/socket-cli@sha256:9daf22229f4e24bc97f01d4fe8842a0ae0dfbac7cbc3993609e0d47a38199a14
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/socket-cli@sha256:25116d947824e17d0b4c4a0348cbf075e97c7cdfd8364f8b21632dfa465788f0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/socket-cli@sha256:5a717ab90356318377fa6a607687bf9e2680b9a8901cb9fb1635fff4ff7d76ec
SPDX SBOMhttps://spdx.dev/Documentdhi.io/socket-cli@sha256:4fae06ef9d99e6f9e2bde4693fa5318aa05f1d921ba03ef7bac9f10d0eec8a1e