dhi.io/vault
2-debian-helm, 2-debian13-helm, 2-helm, 2.1-debian-helm, 2.1-debian13-helm, 2.1-helm, 2.1.0-debian-helm, 2.1.0-debian13-helm, 2.1.0-helm
sha256:de5ca30824fcc38687caf3b987d86117c2a727de56ecfccc80b9f2e52843438b
Manifest digest:sha256:9036cd972f65c836d571ea147259edb1103aca03d151d9f1fe3b386f53320350
Size
89.32 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/vault:2-debian-helm2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/vault:2-debian-helm --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/vault@sha256:519ed45067da2d462ada80c8482278be08d65434ca0b27a18df6202048e1b8ab |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/vault@sha256:95130d123b95fd7fb98499e30860362c46d7680be3d0e10b7fffa74429c22fc5 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/vault@sha256:e2894404113456262b369472431438e8af0ea1c55b3e76561140b93c837275ca |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/vault@sha256:0d2aab23c9953fc825ff6ad8bf18792be47396607960c1ea9992ffb10967aaed |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/vault@sha256:dc1fd3cc36c2321cdbd6347431aba7081c056877afe06b951eb94fd6044b7f92 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/vault@sha256:fc3017cf3f7aac0ae4d3a0a148ef21108089eb069661945b65c9dd0208a9721b |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/vault@sha256:7288fed380a5082bf279c564215e99669df1ac38914825a87aff0ab12d3bafb4 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/vault@sha256:686bb39c8a4be12b6839092a2db3854dd7ee4fb8852288d5feb5b1d9fbef49f9 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/vault@sha256:2ed2458c7a2abe61fcad4c4c9366a0cc0e80ea0a1b4325c80f0217ee86af25db |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/vault@sha256:b040143f0b3d2dd7149b31d97203fc88b247af5910d4b967ffccd30121cfd7cf |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/vault@sha256:1e4f0a42398f61995cdff93c0f30c84dd18cf818d931e6ed5ba675b0c4a92b83 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/vault@sha256:2825f08bbb33f60b29f5fe0fe7444ba2249c38c89a0d90af47c012a421340768 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/vault@sha256:f15065d05f97d38c8045f4154c25784270b19d37ba4de9d102e9fb2b7a2a4105 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/vault@sha256:d9b28c8e1071119e709676730c2411c877ef61e28ab6acca4c8b5a3a99eab994 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/vault@sha256:be748f01331b9a08867edaf54226b6ad318e55af78148f4a86a52cf64eed60b2 |