Sign inSign up
Vault

dhi.io/vault

Vault 2.x (compat)

CIS
linux/amd64
debian 13
Tags:

2-compat, 2-debian-compat, 2-debian13-compat, 2.1-compat, 2.1-debian-compat, 2.1-debian13-compat, 2.1.0-compat, 2.1.0-debian-compat, 2.1.0-debian13-compat

Index digest:

sha256:826a66dd145e8b3254a00ddb4598b05a75caa44956c0e71be4eff7630b7d0cb6

Manifest digest:

sha256:ee5da0e767b90c597197aac684c0462ab22a2456195c91e5d4e7fc4e4a996978

Size

90.83 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/vault:2-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/vault:2-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/vault@sha256:c02e60482f56f711285d59eb9ba195bae2d60b58100b3b08232a7299802eb837
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/vault@sha256:369f4bd0827a823cfd195a26f063cde16cca5243cd0df33fbd821e81d6c6baaa
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/vault@sha256:1e80246a0b3c1a1a72c4e7fd06a1c883719fa7d5ee840b43311d0b8d2f6df669
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/vault@sha256:4c4a596dc250f9dad2c60c6bfe0b137bd0c910ad23023947bab78a9ef24a07c8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/vault@sha256:ca25242034730e3df6c1ff03427822f4093393bd902a2bbc6d0fd9feddd94ef6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/vault@sha256:4307f643960c14e58a70a796323bc9a67954420262dc3fc81042dab3a6c404eb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/vault@sha256:80bbf53e6c8425bb44434e5cf6a2e6910bd843ea10421c16a4d26e1d1350a68b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/vault@sha256:793c9303506577467b4168f2a0764822458b635bca3f55dc3b1436b0ae7e1f39
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/vault@sha256:22ecd5a9b4c4c006bda32a740248c627b5470a835dbe07d44404bf048e063ffb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/vault@sha256:fb9efd22fd85b6fa302a57b27f0e1ba9829e5c04d51b841d95e103dd822e960f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/vault@sha256:e16c8461e9774f64602f6fda47c074cf38a6862b1b013c6bde2f031a464a2d9a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/vault@sha256:18f0d646e06e6bcb087d8abb4fc18366af2301547a5852ba71b2c17a594dbf0b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/vault@sha256:31d0f6355c28664880591b24284d4625eba172d899f89c9a411b70075c81c486
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/vault@sha256:6bf6e43305d1355967cddfb2db4ceac29455c480d9479ddba2b8f703687e404c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/vault@sha256:f19e6593e098bb7ea5aa8922541ba8f53e5a50353203439a357d2a33cb247333