Sign inSign up
Vault

dhi.io/vault

Vault 2.x (compat, fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-compat-fips-dev, 2-debian-compat-fips-dev, 2-debian13-compat-fips-dev, 2.1-compat-fips-dev, 2.1-debian-compat-fips-dev, 2.1-debian13-compat-fips-dev, 2.1.1-compat-fips-dev, 2.1.1-debian-compat-fips-dev, 2.1.1-debian13-compat-fips-dev

Index digest:

sha256:b47021381b2d0e899cf1612b5377d91a27d0538d27911f87e12c64cfdd233db6

Manifest digest:

sha256:1d2bf4718a98f856d4434b77dbb077f619c4cc403cd27d5bb5e9f725603c380c

Size

179.35 MB

Last pushed

5 hours ago

Vulnerabilities

0
3
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/vault:2-compat-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/vault:2-compat-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/vault@sha256:d5f56e28bf1a268e8ed651510b14ae7bf86ed88300441f8e7fd5ad091b578259
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/vault@sha256:17c2cc84bb0865b681173a1dfcb176229f0e727cfe7573b965aa3005fba73ea5
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/vault@sha256:6c6cfcc699fb5ee3d9b8562a0d409c980e2bcdd78537c4d979c9a9351f5de10a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/vault@sha256:bf06d99ea73160273e74bd9ea0b3a9dc6104f0b7eccee1bfa810f91be8359784
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/vault@sha256:9583facd6135effa6010270f6e88badf4b5c1b5e66ad096f38887b0961fade88
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/vault@sha256:c7a204b53f993a4fba34fb692bc3dfbbcbdb8724402dca8bab887bf24ec54325
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/vault@sha256:e8963d6f1bc54204eaf4235a14b4d33df5e0ee4c4f088daa916ba00b75ccac0f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/vault@sha256:6bfe246be74d68108483fbac115c814e735ec8868d2fcc2546478ab65c7a2909
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/vault@sha256:0d1313505fccc03d9362642059835714a88b7f4bacf0200f1b72edae8d23bb6c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/vault@sha256:d60a5d58562f37fd2b37794c050f33e52d0eaac5e678578d62496075e1e1a5aa
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/vault@sha256:2c8ce4a31d6536c262c63d4d2a07559dfcd8ffee12e753a64353ad0a4696b15a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/vault@sha256:74a33e51467ca70df096a2af8d864173123e3030b1ce3b400fdcb2a6ad55ffd9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/vault@sha256:f7b44a729ee10273480aa6bc60e40e7e2b5b03fe6189cdfe88dcea2e10478d38
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/vault@sha256:407e700d517a2f32e27ce8b8edab2ea0e6c9ea09871d1c6ab6630cf85d7cd980
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/vault@sha256:1d672348d26ae4d6c1467d08297010eae235093dfcd80254012671a48bf31795
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/vault@sha256:bea6a40a5b9642754344b78870394c6cada67263660a8abb44ff00355f6cf7da
SPDX SBOMhttps://spdx.dev/Documentdhi.io/vault@sha256:9e9ded83e984f252704b2aecf3d244e5d522f609693423900254989cfc7bdeb4