Sign inSign up
Socket CLI

dhi.io/socket-cli

Socket CLI 1.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.1, 1.1-debian, 1.1-debian13, 1.1.176, 1.1.176-debian, 1.1.176-debian13

Index digest:

sha256:263d593cb2eac5886665084dfb4b15327a073acb1028a9013fb33eda74e14c55

Manifest digest:

sha256:24277b18e0da9a3b1c5c54cf3caf602dcace84c8bc3c05c3749cb913f227e08c

Size

46.35 MB

Last pushed

56 minutes ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/socket-cli:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/socket-cli:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/socket-cli@sha256:6b2bf1864a28425776270f6a5413318476e12b6450c8a66157b14649095054ee
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/socket-cli@sha256:861f8ac4f2d44b77bf11ab584d282fee138f772a3c95e4fb7559920326610210
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/socket-cli@sha256:d9ddf98fe7c044e0c348809d218ab8d60145740df22aab97d0cabccc59cff3d3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/socket-cli@sha256:c1ece7048841595d570701706aac4486d65a3fc4d164d55a7171eedce13bfac1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/socket-cli@sha256:77039054640b015c40d9c5c9c0f02f6628e029c8b44f94c78882f6ce97960079
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/socket-cli@sha256:408bcafad7a6b1a3020a8d8ca061fecbb01078b1a9b69cda5cdda124187a54ea
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/socket-cli@sha256:64a845d4c270a00aff0efb14f233c275110b7b66e9d656c992552aa24eff56ae
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/socket-cli@sha256:162b860fdf0aa1c3dee2225d11219a38c7054d1657a54bfe51e30174c690e63b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/socket-cli@sha256:87a3fd430ece63c064dd9ea5dadd70ef63ba750b0c2539ec48ad88c050ce4aaf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/socket-cli@sha256:422530d78267755050a96b7155c3e1b3c9ef2caab04f5ecaedcc0d71fa800a3c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/socket-cli@sha256:42ff6e74557d9f196fc74270bd82c6f247e032c75009189d3b4fac7862b8d5cd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/socket-cli@sha256:f88dcd42d73d7944bf813dce6653bfeb98d1672a84a396c3fd171aff1b66c56f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/socket-cli@sha256:b55f91504901031acd3aebd989d45b5d5ef663a3ba2f9828c77dbefe7429e744
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/socket-cli@sha256:e48a035cb4680769c0becf35dc7203fbb799b781e4575d931ad5a7a993472da3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/socket-cli@sha256:88a307a47fa2ab6a838e51eafc166d48532fb4d181e18b0dfc93c51833f246ec