Sign inSign up
Vault

dhi.io/vault

Vault 2.x (compat, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-compat-fips, 2-debian-compat-fips, 2-debian13-compat-fips, 2.1-compat-fips, 2.1-debian-compat-fips, 2.1-debian13-compat-fips, 2.1.0-compat-fips, 2.1.0-debian-compat-fips, 2.1.0-debian13-compat-fips

Index digest:

sha256:4323e9f2cac78427b55ed397d595ad79d43938f143b0fee0424de387848697a1

Manifest digest:

sha256:2b98590f90cf57b83c090a0cc6d2d5cf96da4160edbd530981d28cb8c3712efd

Size

93.23 MB

Last pushed

2 hours ago

Vulnerabilities

0
1
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/vault:2-compat-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/vault:2-compat-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/vault@sha256:8622077c65ba4e990c820cd9c1c72fa944a849351aaf8fff67141e7e925d120b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/vault@sha256:fcc15da38aecf3cd30082025fe29df438bf1b7614c338a4fc2fa782336df3d4e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/vault@sha256:becbc37e26667b019c1ef64b1032189922b23b80734be69d6085fe413be29bfa
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/vault@sha256:5022d0980e17a9f2644a07c66a5a08d5b9af29464b07646e90d5766fe4bf3b5f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/vault@sha256:bfca2bea87ecf0232ee2a472efc8f3a64687d7fbc1f5e961cc9f1dfc9ca89ef9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/vault@sha256:4a18f52af8f8d5c4bb3788b11f13393c1e1e38c6ab5ef2126d8edf42437b65e7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/vault@sha256:72dabed83778083c037bbb7034d4bb5f4e314f542bdf46139ac89ae906cb1104
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/vault@sha256:7e8d7179b8c230cbb86673b7efea11272302419c7167becebd71b44efb6b8ec1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/vault@sha256:076649f78f6bdf2d8c9c2286e1ba8eb723c9bb879c4db39b5fa721d350d8f094
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/vault@sha256:0db91389ccdd4b6de740acb0531e221cccc19f9e32664a7c14e8b83685586389
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/vault@sha256:ab4388dd4e9d7afd21cd9958d9c2bf74d217835f2e2850864bdbc3ef4ec27d44
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/vault@sha256:c368b983850448f0ec6d01030626ffcd0e5212da6cee40aed44f1bad5faf0672
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/vault@sha256:2a40414de658e7f4ecfa5b06e34a9892ec98222d93132932a530a604e9460671
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/vault@sha256:7e42416c3a9b9d0342e15f573e452e665bc729071b3e6bc55b02b750d2c74aac
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/vault@sha256:01fc484df3ff90c4d7a0856a10048ae502f51f4368112924c135572cba532c9b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/vault@sha256:fb96248c43a30defdd1703170bb7b4766bcba9d195c465c06da68225d38f7f3e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/vault@sha256:b5a9083836e9827b13eb1036acb28bfaa186ce1f8b38c29372e284cba65d17da