dhi.io/vault
2-compat, 2-debian-compat, 2-debian13-compat, 2.1-compat, 2.1-debian-compat, 2.1-debian13-compat, 2.1.0-compat, 2.1.0-debian-compat, 2.1.0-debian13-compat
sha256:b1d386440b5dddf81b35da10a080f9b968a81097b90771bfcc7a5d98da82e2fe
Manifest digest:sha256:162e4d9f5a227ad79457e42934b1c4396a6f9779d84cf1f500b23ccf46780464
Size
90.99 MB
Last pushed
5 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/vault:2-compat2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/vault:2-compat --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/vault@sha256:b7380480f81567815dc42b8421ee007d014a4850cb792ed46d0ef3154ef2d9a0 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/vault@sha256:e1b14d2b5431b01919067bb755437bf31f158a4105d5282cc8c874ed3c7eb31a |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/vault@sha256:a8f74e6678f9c92e6ba3f5acbd48cf8cd942165cc71647ed6e8ee08649cf43f9 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/vault@sha256:d0c4900796815437cc730614f4e5cab8ad8dbad11a9c01e7a81fecc00b674904 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/vault@sha256:40624601966a6e461ae2d0f1941605bf3d4cb0f313a26e678a137c7b821bf94e |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/vault@sha256:6d63f3135585f2fb535f93e55accd0dc574bdeaa8f267f022b2e9bd2dea06aec |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/vault@sha256:4cdb2f89fc8ac876f5e3f5e75c9e8d36e1e9d11dcb3f7d0563ecc5e32ac0e05c |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/vault@sha256:0695c07b154bfa2f3288469b8e6c356935a0d1042f65dd67a34e8f3d1a87e064 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/vault@sha256:49658518829bf7739f9299989819af7ce534ba69f5056b5cab3e47c9be3c6bb3 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/vault@sha256:de4ec0cbdf7201ffd0fe24568d6888f02fb8bfa05ae88ba4ddde80e2fe717387 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/vault@sha256:495b4c4fa1f91292050bf8e2b58f6d46dd727ea9105a6afeb86222cf06a147b9 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/vault@sha256:54954affd403b8beded6d2820d4611aed55192d36bcf788d99bc14ea0c19c4ff |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/vault@sha256:6129594da8a89df59fffc9c643b73f32ac21a83f83ad9e6b9176f160ab425b31 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/vault@sha256:c2d9494bc0f73c35015d8770273c6675dccf3ab3bfb9bcc640dd9de849449daa |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/vault@sha256:ac860e309ff6610d703e2a21997f1ef1d325cf13d60cddf820f7ec5d8c6ec555 |