dhi.io/vault
2-compat-fips, 2-debian-compat-fips, 2-debian13-compat-fips, 2.1-compat-fips, 2.1-debian-compat-fips, 2.1-debian13-compat-fips, 2.1.0-compat-fips, 2.1.0-debian-compat-fips, 2.1.0-debian13-compat-fips
sha256:21dfc3a824e721562787a095505642f0ef5a4e450e99ce37200223164a8266d1
Manifest digest:sha256:e272d4750a2d0f69f08171d66b9a3a24e88ce63aefad1a2e673b86c40874dc93
Size
93.31 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/vault:2-compat-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/vault:2-compat-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/vault@sha256:2cc7bc31ed418ac5d64100f04ddb613836583c678ae33bd0bdd2d018c370a132 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/vault@sha256:81dd09b2e012d302deff9e25d49684d52b06c37013528e34f50ea4b9f19bba1a |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/vault@sha256:53399e260c2983a75a651ca9b2056e538164078c255fdf4ccae82252e71d2230 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/vault@sha256:fd91f7f20e9117df5f773c305a6e0adbd34a036a9751337c331ed2ad07e55ee4 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/vault@sha256:3471228125993ca44b00d5f03db098f3107c435c23ff78cd96594e405d55fdbb |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/vault@sha256:eb2f246509624dff653156a9da01514dfef080039d0a8f0b0c6acbd585ad989a |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/vault@sha256:08326f435e9c8c7d57f7a870ea0f7e78192cdfdcbe860d85520901c8b88d1b3d |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/vault@sha256:4f26e8e4c3dfc1c7cfea723dd2f9a0980d607e69ae41c187f5d4bf1a928af88c |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/vault@sha256:0c35ad2bd79cea652186251b4e2e934bbb3bf389a83bb83ce0ae0b3f06ae9a89 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/vault@sha256:61e63e58934075bfb51cb15d233b4d00e095f330c71facd1768c8827141f5b61 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/vault@sha256:26dcbac5397085f18e5324521a6a7f55ffe2f632557d9fa68ecb63db7a6957ef |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/vault@sha256:5a2e351b51bcfd67d2ba4ce0505151d6fa47cf7e1759fb6d1b2accbed30ea638 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/vault@sha256:a6471fae30bbccb7bf49aaa690ec42cc748e3c9481fe2c678742c6a1e534c890 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/vault@sha256:1e50c55064bafd52b8a9ad85a86e052bdeb6652706d9e8865be8531da178ef8b |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/vault@sha256:92a65297be8794ae1734b4337f5de5e6995ab88eaa9bcf80105d09a320185bc1 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/vault@sha256:be819d945d3389a8fb76329d3015cf1f5b401adf9bcb8e4c24e35ffac4748812 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/vault@sha256:05d0e09e3d68765bd8a4899506deba83391f1e30d766b95367be4274332dd1dc |