Sign inSign up
Vault

dhi.io/vault

Vault 2.x (helm)

CIS
linux/amd64
debian 13
Tags:

2-debian-helm, 2-debian13-helm, 2-helm, 2.1-debian-helm, 2.1-debian13-helm, 2.1-helm, 2.1.1-debian-helm, 2.1.1-debian13-helm, 2.1.1-helm

Index digest:

sha256:84cd90f2ba372cf5ec6892ccb6d87aa3bb57a0f1d16a3ac00b09ca164a90549f

Manifest digest:

sha256:a0d23b229e0f242efee6118ee1f6b462aca39534ad6ca4b75b94f607f742e0ae

Size

89.57 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/vault:2-debian-helm

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/vault:2-debian-helm --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/vault@sha256:446d7df470c7b41bb06af05359301d6f6e208ec45d051efe48d39af9b294dc7d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/vault@sha256:6acbec8db27e2bcae5c02e8d5bd2c397c654b703852a2d497e7a6afc6a2e129c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/vault@sha256:375b25ce626ba4c955709977edfe85fa7f0e5a3edd96d1d2503471ce89850735
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/vault@sha256:678e6c6e570302e39188188261e373c89516395d5f5b67a1cb81226f948ef071
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/vault@sha256:9f9ac69c24074db85b585e3746044bd48629182d26fdc11c291125c5d0775bbf
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/vault@sha256:1d69df4391d13433074bbb551777a1870057b39108c59e5d6c3e0221414af23a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/vault@sha256:b60b8b59c0e9dd290b038fcafa38a33890b76e5bc03d3c34e5f3e07a0850d233
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/vault@sha256:ab7ecc6ca108a5f4bab88ab87603f13a7cdaaa350140d8c9113b9b2e8599dc26
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/vault@sha256:9f7b4ede4d3e9871a16aa6eca042a8d946c445b36bbc2648d3dfc517e27a9431
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/vault@sha256:3920c98b955f92881583112b2172e8e567262950323bc077a53eb0c552a0f943
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/vault@sha256:0d7d80b24fcebdd4a61173c2e8a302499f81ed71bbe5df6fc04d642ff17f57ca
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/vault@sha256:21b221924a0a3d0a9555adde76f0118bdd29b10c190e716a4b17c8c0ee37e9eb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/vault@sha256:6a0f5664f838cfbb123e8c7ed15db938337285ceb5eba94934d20f0f73dd5c5e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/vault@sha256:74d5aedd40994cebffcc55d1cd7894fa9e09c284cef0b54800ab3f621c6c08e8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/vault@sha256:bf1a96e4c10fe2967e818894a513ec17a99f8d33d11d91745d03992fd07bdc4b