Sign inSign up
Vault

dhi.io/vault

Vault 2.x (helm, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-helm-fips, 2-debian13-helm-fips, 2-helm-fips, 2.1-debian-helm-fips, 2.1-debian13-helm-fips, 2.1-helm-fips, 2.1.0-debian-helm-fips, 2.1.0-debian13-helm-fips, 2.1.0-helm-fips

Index digest:

sha256:8f97f79bcd8b9b918a71697a53024b6db66d84c7580e56c495beef20b359c06a

Manifest digest:

sha256:8a1ac1ad2f8bff0bb65806aca720275da739650c199d2f98d61b283cf229ab14

Size

91.79 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/vault:2-debian-helm-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/vault:2-debian-helm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/vault@sha256:f957c7a65401ba2fddce2fbff1bfdb39dc57dd4161b1dfa67ed1422e5e4c224e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/vault@sha256:b610c211deb726a2d81a3c29426985a6a72ad1749341656898a5d33716477dd2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/vault@sha256:a97032016b229462d96292fc9d95424c123da5c4f93a437114f394d7668c27df
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/vault@sha256:534daa0f4bcf8184a5ea27f517da50a454e3ef1b9077a44fae950228a8de06aa
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/vault@sha256:5999e97d3ce5ca3bf770ad4cb76b1a5a415d7e7842bca51de24987611a7bdc26
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/vault@sha256:02b29111f1495a35f17e51b223b476303b7bf3b4efcecf51890470b0b60ef3c8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/vault@sha256:542570a8572601ed7533870dba34486b20d6deea80b96981894c201b4b815875
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/vault@sha256:48b4dc4180c5c142aacc442a7670449b94b736f00cec95e2dd03ed1f8a80dd90
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/vault@sha256:9a4679cef7e4354e0a0752bb4ce5ac6dd6fc1d4ea6f8bdb1cf61ed1e608a2c29
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/vault@sha256:5a28a69032e7e09de9bf7d77109a5cdcc996f385a1228f083c0e9a7a3317b33a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/vault@sha256:9e1de75deb1a20dc6ff68c8461cb3dedb68a1aa0c91202995df07969d0b70f3b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/vault@sha256:ddf8e6919d5bbb2070a10d665d8ebfe0e4ef7812dd621f05ca7e01480cf2f381
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/vault@sha256:d9ac857be862d52cfc05a186c7b3b7bd19af504d5a9b738d0912e3da83dc1ed7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/vault@sha256:d31c94fd71a5f206139c40ad36eac9fa9a00a65e8844b1b43487f149d2e9ad66
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/vault@sha256:1efb5b3591b4b972b7c044efff35bb82d405928b6a74fb118d3584ce57d704ca
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/vault@sha256:0becb0ff1275e26ba8de5d5418b8bcedfa5e87d9041b78c3b3e80902fc4e556e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/vault@sha256:cfa6004b16454733595c9162323abb8b86525da7a65e1773e11dad447f939f57