dhi.io/vault
2-compat-fips-dev, 2-debian-compat-fips-dev, 2-debian13-compat-fips-dev, 2.1-compat-fips-dev, 2.1-debian-compat-fips-dev, 2.1-debian13-compat-fips-dev, 2.1.0-compat-fips-dev, 2.1.0-debian-compat-fips-dev, 2.1.0-debian13-compat-fips-dev
sha256:ce5575ff17bc857ecab7eaf727be50083842baf493b2543dd41b7119690a7227
Manifest digest:sha256:8fb7c460c2adeae61950a6a39efd8fc476fbb3b01dad6799b49188c379c366fc
Size
179.19 MB
Last pushed
1 hour ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/vault:2-compat-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/vault:2-compat-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/vault@sha256:3d1590168c4247ce8af9835d94fb5db447be4c639691fe9890b362ab6a359f8b |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/vault@sha256:2e0761bc2990c98b6b17ea960bcb8e020c49f852e28b0d0e1ae87881286cb291 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/vault@sha256:bffe0229f743fea1ed1e94902aa5d1e703eec77de149d2598111dcced3083b53 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/vault@sha256:a23a3a999985ccdc456f245c4e2dca16dd3b72d94ae61d006fd33acb894f212e |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/vault@sha256:fcfb6ed66b6e10b6cd2d15c9f5efff5b44c17141b6f3126af87f508c5aa21441 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/vault@sha256:44a50b9278b7999d865e99a13bad9988161d9ac3e2e48a44b729f47b806b081c |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/vault@sha256:19e5680e98a1ecbf8726ff125d32458ec912664baf41c9871e85116a1ecd98e7 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/vault@sha256:517a51e105f1dd93366f0d7eab6b6e6d59a5f95ce87a5a6cc383bb1bb506d4cf |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/vault@sha256:ab8ef8ff934839a4bd0223bfaaa9b7ac961a6be2a28527d13b132dfd36689dbd |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/vault@sha256:151b46d0cb949b2d2b63e3a8960f37839b6674f4101067f67746bcb901a42927 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/vault@sha256:2cfb6353704b118b789fd6cc21ab29d951b3072bf0e9051a8329e959d4105f6a |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/vault@sha256:24c2105ee76b60be55a400a5db5d6e4d8d37dec09cd2523d03f5a4985cadbc91 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/vault@sha256:6892172e33058b62c6baa3513bb9ce7a0b3f592fdcf3ca00c88c69891b225e8b |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/vault@sha256:b1350d6d11a8209cf66a21d1a07ec59202582d303c22bb2b1bd8e67286b5b303 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/vault@sha256:666a98c731e53460070e05b46be17e1f1c547f24a196d8c52a32361de2a425ab |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/vault@sha256:e2be46822a6fb12a531eba00b69064551de5fd7b7d7ac5772ab97ec8317b3fbf |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/vault@sha256:e9474b316341fc74738ef040357d50a4b1b4dc07be9d08a910c1156f6be69a8a |