dhi.io/vault
2-debian-fips, 2-debian13-fips, 2-fips, 2.1-debian-fips, 2.1-debian13-fips, 2.1-fips, 2.1.0-debian-fips, 2.1.0-debian13-fips, 2.1.0-fips
sha256:a4d6c131717e2d32e5d93d541be1ab083686441bbfa9bb583a77a6a59f4e9e2e
Manifest digest:sha256:5997c5de2752f58535c0221765e8bd203205f82c23e0d1986ac20c7ae4ca9998
Size
87.55 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/vault:2-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/vault:2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/vault@sha256:55326a84f18963c45b550d7e644feae0e3ef242af0e4b95d344496c7126ed76d |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/vault@sha256:e0c4a0ba4c61371ef1d5e83b71545aad55ba97d4aa05c1f3fff7cf083e9c327f |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/vault@sha256:b7bfc46db24bb951ec29f633ef6048a979fd50bf53cc15ae82b32cd71fa5c1b6 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/vault@sha256:43238d62badfd31b3148da0fb29dde4b9ee1a46b2a3f1163596d7ec68fd4a767 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/vault@sha256:a3d0c083367e8b080ae5cc964619800936c0a28403107badc3edf3aed366a11b |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/vault@sha256:8f2089bcf0aae240e58c02ff2dc1781ad3af577391776f16cf52caa4c3a81119 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/vault@sha256:c057e8fd04b59b77dcd5e55f0af1910e8c78456dd7e95eeb746e65fde29db0bc |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/vault@sha256:e1489a050dab5116dd72e230a107b1589b328995b255c498b120e9e521322478 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/vault@sha256:b91b741e858e9139e89211d56038c6797eec31f1913bebfd26cd32ba3a3ef857 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/vault@sha256:27057d12d925402a8313bd61fae958d58c64d148c675583b2def486162196abb |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/vault@sha256:d2d01c33a99007f34bda8e1ad3ab4866c855db6cc5779d062a958f075ba7a699 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/vault@sha256:9f55d03239812be67f6e1e3a6622abb192af078fc86f2c53428f39236171b25f |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/vault@sha256:87ed796128b0c80518cff0fb03811e4bffe240c3ad2ef26be7766e5314b00664 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/vault@sha256:5ab47cbef9e9ed1defb253866132625dc2a995cc0fa1be844df33634947142e4 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/vault@sha256:f07d9fbe5ca375741baf280bf1d0b2553123edf6754e0e0c14b0377c15d2110b |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/vault@sha256:c6ac695353d1e3f91ca7a62384201b4525342bf9fba75adaa9ac8a7185e375c2 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/vault@sha256:71d15357ea587737b2df5f3df0fdd04985397aa2ccfcb90483ec935e553ceee9 |