Sign inSign up
Vault

dhi.io/vault

Vault 2.x (compat, dev)

CIS
linux/amd64
debian 13
Tags:

2-compat-dev, 2-debian-compat-dev, 2-debian13-compat-dev, 2.1-compat-dev, 2.1-debian-compat-dev, 2.1-debian13-compat-dev, 2.1.1-compat-dev, 2.1.1-debian-compat-dev, 2.1.1-debian13-compat-dev

Index digest:

sha256:1ce4827afeb5f17ba25c4345238bec73b691a690cc0155a616f93094461a02f6

Manifest digest:

sha256:b7bab6bbdedbdf14302ad3d2613781548af2e4d07ec41c0a0904c3cf964f7584

Size

178.61 MB

Last pushed

13 hours ago

Vulnerabilities

0
4
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/vault:2-compat-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/vault:2-compat-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/vault@sha256:7330cfa9675b35310a301a46a0ca66de7aa435d422237d897b26a1e7d4891bb5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/vault@sha256:a8f8472b5febd2c3fef9e0b0e71750dade3b8d6e449bc1c64fef7f7d7bb3b2e7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/vault@sha256:f89059b82d04a8180b3667b80aabf16fe5b6fd6101e16d6f9511d0f497c1d6ff
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/vault@sha256:edcd986f754784ee8a902e56860b40fd5d3c173fe6948bb0cf2557b2b9259371
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/vault@sha256:9550e03adb554a972ca4e07a05aa4bd9156c5edc50e301b82f8e58fdb672d10d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/vault@sha256:09b4dd00d2ec09236070d658180cf150201f8fadf5caf60bacfd0c5ff314a40d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/vault@sha256:84960c5fe9e811867cb287013ec1a029346bb680a99a9a1ffbbe19c90c606b77
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/vault@sha256:5630593f25460c875d6cfaf46bcbb1a51103db9986397e49a875e4a138ee403d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/vault@sha256:f5a30660ea12ddcfab213ba1cbf68c126069184000f1f9b1e4f177a7215dbca7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/vault@sha256:72db9115e1b7d17ba7ca3b28ad5e3b7776ce9bfc849d4ad544a2d7e3f88f66c4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/vault@sha256:3a2742b7ca2783ea6964de6cd5fd40239169a449991679bb4d47a5a3766ae62f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/vault@sha256:d43957f7e5e2935cf1c7a67587f71fc6bee1f59fef5d75a08dc2ed8e830d26af
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/vault@sha256:efd99bb10dc390620b7e82c4db8b7d5de8f624c4cfdc258405a130b1fe3f04de
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/vault@sha256:6957aced0d938660d4a3c39a8608b3a9466908ed01e0147b57a14bae802befa3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/vault@sha256:0bb568709c59d3887194220d785713539073de4f189998d9d7caf711953b6304