Sign inSign up
Vault

dhi.io/vault

Vault 2.x (compat, fips, dev)

CIS
FIPS
STIG
linux/arm64
debian 13
Tags:

2-compat-fips-dev, 2-debian-compat-fips-dev, 2-debian13-compat-fips-dev, 2.1-compat-fips-dev, 2.1-debian-compat-fips-dev, 2.1-debian13-compat-fips-dev, 2.1.0-compat-fips-dev, 2.1.0-debian-compat-fips-dev, 2.1.0-debian13-compat-fips-dev

Index digest:

sha256:e41012f917be7ab46ef367e0d0dce7e19c2a608ba2d61d56b3557ff86de20954

Manifest digest:

sha256:083e6d1b1ee7a89fee900afd56ea3a4e52c239e3e5c7fdd51fe0a8d2e20bffb5

Size

168.40 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/vault:2-compat-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/vault:2-compat-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/vault@sha256:0fd2b10e9bfbc50c943c88951b1f5ad0be27c41e550d63fdef1e1e421cb3fd2c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/vault@sha256:0ff113f3fa0ebb7b45c986a339bdf5fc240b264ffd5ad8686b653c360cb07093
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/vault@sha256:090c605e642d0f826f5f56863fa4d45874216edb9010f2e82106e331ee579109
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/vault@sha256:78f800258eea15381dfa2ab32ba126f0015dadde994dd733b099be78cc221aee
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/vault@sha256:9839fd6fe238e286addb16abf604d78c8f50c3a7379ec84f6f7c4a5c2891c9b0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/vault@sha256:7c5a46140eb1ec7c116a426a8b8d664c2dec663c805fd20e2b7256a65138f86f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/vault@sha256:579ba1463b6b8b0c4bf32791d18d325a6d067671f4d9b1ebda4d5693240c8ad6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/vault@sha256:b1a59c1284200d1654551897117551b7b676601f162996d59c1e5adc038f58b3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/vault@sha256:eb363158aef09b70ed194d19d7394d5eb4d4410c01765f9d7a54480f8d6533cc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/vault@sha256:c0e4e84efccfeb332bf82863ac6cd54e60661551768065cdb7ed0ab1af8ae303
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/vault@sha256:d3fd15facbfd5f91b9c62642220c423339cf5151bf0288dfe26683e64c6d1625
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/vault@sha256:3c1b11ecbec04a69ae7192a74efe7ca569719f6b98be8d8e8b492e2ff61ff85f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/vault@sha256:8ec1a6a0fb7ebad1eee6dd3d4d8d2dad591fc9ba6062da7c0a3a3eb18211ffc6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/vault@sha256:f4c088562b9a88fc915ef21327711a58612c1424b8506d67dc3ce1f615450042
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/vault@sha256:f6faa58f7801e8dc62ac324d97cb668632b598aebe55b8ff65093c91d4cc628e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/vault@sha256:d41cc4d78e3d5585ac91e7b543b189d8d826305fbc473a6c0d52a810e49972cb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/vault@sha256:1206771d60c1592c88943974185b84a74b2179351f915840d9f27fdd0b79f01d