Sign inSign up
Vault

dhi.io/vault

Vault 2.x (compat, dev)

CIS
linux/amd64
debian 13
Tags:

2-compat-dev, 2-debian-compat-dev, 2-debian13-compat-dev, 2.1-compat-dev, 2.1-debian-compat-dev, 2.1-debian13-compat-dev, 2.1.2-compat-dev, 2.1.2-debian-compat-dev, 2.1.2-debian13-compat-dev

Index digest:

sha256:f4be612541b6f8eee25211b5f8222d8b0431b3bd0ba31d49a11b4014c089958b

Manifest digest:

sha256:1a5ac22f1e48ec58939f6319ab49aea500ae5bcefc294f5e510134a62894ec14

Size

179.72 MB

Last pushed

11 hours ago

Vulnerabilities

4
10
5
3
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/vault:2-compat-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/vault:2-compat-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/vault@sha256:d1c324defbf38dafdbb3032f74f77fba7650827d01f2ce4a1c3324c1d2320f29
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/vault@sha256:3b2dbd1a039b80fa48a39255d50456f4147d5bbd46ff8d2c0b7f11bf7fb1406f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/vault@sha256:f21b34e8b8d438530294636a9e64534c9b7a3171d537b25e380021b6cf7da753
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/vault@sha256:72e4fdde078596c264b0f5e415dbc51ea4e926bf37ae76c31a6cc29f8a5fb3b7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/vault@sha256:239ea4ea628eb791d89ffa44d1b12d1af8aa5e2697992100cfcfbfe8486708fc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/vault@sha256:c95ea453c68615a7d2339fed728fa2afbd60b19bdfe416bdef5dff547dea5e34
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/vault@sha256:ebb79762f885c447b798f5c9dc3cf1ce0db320136b34c792e1344de7b95b1bf4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/vault@sha256:52a624934d22f32cf569308250fad353f448821ca2b107ae881cb16cdc92caf7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/vault@sha256:57f38c7fdeb0857cf5f3e15df4a7bc390dade7c224e0cd0e57ab47dc6db0c3a0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/vault@sha256:484f8287a9646389c01c7f04763dd2b41b69a134bc9faf0a292b8adc67622236
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/vault@sha256:1996db1f6e9a086da74628f1596190c42a27eaaedb467d85b5c9b4db6bfc5837
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/vault@sha256:7b78bcda664c04a2c6b2b08248ee188a8384fee49b64ad12a7586745b7e71e67
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/vault@sha256:5cbbb4ba06cdc5290d30163a62bf25e40ee2eed06f3521658a84cd423fc6fdf1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/vault@sha256:9686ec108e1c890e72dba5550aa00d6e24e4c3c8c502bd60765536e0f5257fc2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/vault@sha256:ecb2857f0019b8c3db134fbd0beb83725e50e39f28e6e0b96df75b765105dc44