Sign inSign up
Vault

dhi.io/vault

Vault 2.x (helm, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-helm-fips, 2-debian13-helm-fips, 2-helm-fips, 2.1-debian-helm-fips, 2.1-debian13-helm-fips, 2.1-helm-fips, 2.1.0-debian-helm-fips, 2.1.0-debian13-helm-fips, 2.1.0-helm-fips

Index digest:

sha256:86528e476b6e8f9e42d6f5611fd744b317f71ac28870dfe80478398bbb64ffc7

Manifest digest:

sha256:36f7c570f2a3e7a92844078c02927c31448b2468dabdf116225bccca61f2705f

Size

91.54 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/vault:2-debian-helm-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/vault:2-debian-helm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/vault@sha256:91331d033455e6f6c6d2eb34176484992c2280624c6b4b108201286fdc471549
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/vault@sha256:c02e54d6c2d70a9a75e252c2549c6f229f231bbbd74600c5317a8f5e77d847cc
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/vault@sha256:afd2c0d1584c70918311adbf23598e78e6af9a4eed94d4bc064135cbd7f0a61b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/vault@sha256:7812aeedbdb26953599483c2646af2a402255213d298104080b45a075ebc72de
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/vault@sha256:20a1ae6f0a7fe6258ff8a51ddacfb34b1e6f04f71a4fc53e8145229612b99056
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/vault@sha256:173d8fedeae23c52a081297b9f03e2c92cd0bd0182ed4c54e0a3cac177c2fed7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/vault@sha256:2c1a08fcb568d3ce230fd51075421510d62d23c1bb24f298d49828de180b068d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/vault@sha256:a465a959cc7890bd674b7f5df64600914dcd6fafe4ba7b3225f8fc72bdf785bb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/vault@sha256:04eb25083e3af80a0a10ec8657552f0b44dfbd7737721d1ae0848aeb7c3c7826
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/vault@sha256:aba20308f47f3847c3766f9930008f66eb574734acdc41167162d057f8d9391f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/vault@sha256:fdbe48bf8426b206b160fef17b777e521ea8caeeb28cc6d8d756ffd99e6c4a47
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/vault@sha256:8650db1b728e6f4bcd87fdad57f01e108e7294942ce7489d867bf7d7168c4dc4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/vault@sha256:31db6e151e98408e0b4ee644754fb996b5b1a4b2f07de44855e2bf7b931bfc3b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/vault@sha256:c22bd3dfe1425b0ff64d470729613832ab4398d809bfe043ed541d3c3f7560a9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/vault@sha256:659502d8b79bb81182f7f6ef4f605598fbb227359ff2e61050a8b1399c944444
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/vault@sha256:1cb9018618624bc3b928064e8824e22f00939addaa59c04acfe8169ca8b1d353
SPDX SBOMhttps://spdx.dev/Documentdhi.io/vault@sha256:6dd461c801ec10e763d8449f428347de2778e13a0b4f1aca967d5aebdab4b3bc