Sign inSign up
Vault

dhi.io/vault

Vault 2.x (compat, fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-compat-fips-dev, 2-debian-compat-fips-dev, 2-debian13-compat-fips-dev, 2.1-compat-fips-dev, 2.1-debian-compat-fips-dev, 2.1-debian13-compat-fips-dev, 2.1.2-compat-fips-dev, 2.1.2-debian-compat-fips-dev, 2.1.2-debian13-compat-fips-dev

Index digest:

sha256:bf6b6744377b7e17b66c3283a3803e0cd4c8c96b5275a19b3439e41199ba38e1

Manifest digest:

sha256:92cf7fa590c5045124c2585053eed8e0a91b819a02ba3439c5bd6ecb2fe3e655

Size

180.34 MB

Last pushed

8 hours ago

Vulnerabilities

4
10
5
3
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/vault:2-compat-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/vault:2-compat-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/vault@sha256:bab7c430b1f354815531342eb4b7fdc9330c0d4c917f4a8cf185f500290b0f54
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/vault@sha256:c03b3df76a45d1244ac25851877ef5800bb61dd76f9bb29faa6bd60156ba2e40
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/vault@sha256:f9bd70078b942150d786eb5f7c14e68e5d90d68b1b03cc1ba2857e7d21c14430
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/vault@sha256:07d621f7cc716398949a5ad031a84009dc03f63d1db3ba55f3357c3a9c737571
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/vault@sha256:f3cb2d0e8415f44672588dd9a7cf925ebbcfeb3dd818eabb165423c4d0939d1e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/vault@sha256:d4ff798c4a945b84b75a74638eb0ba79a5be43ccfacb1b8fada599a4ee0978c0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/vault@sha256:fcdbf0b2a3f752269509d742531248dc2c9c70ea05d4f48a58781f6428f32d54
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/vault@sha256:69b10aade2e7e791f8e68391e6863145a2a2560129bbca653f8e2fa8775e5698
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/vault@sha256:7d7ec1ba845ef74c3b5cd5ac78c77b81bdae87860eb184f8a420de517a65ebd2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/vault@sha256:76a708682be1852efc625a9e5a90b12ee516dcddfbccc05aef59983aeb3a5017
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/vault@sha256:77e3c884371865db720225c548cb64c0546bd7ed33ced70c83103b2c8741b2dd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/vault@sha256:9b9b92ed45b81868da42c079e6936d8d8e0bbb33a865bfc22000d540b1f43df6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/vault@sha256:a33bb6d4d8a0b75e2482b2ed7ecacf0680243dd0500c3f02c0c08551a8eabc16
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/vault@sha256:f477cf8d740ccb97339315681f9a5f4df5df84abdb7c6caaa06689f8503265af
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/vault@sha256:f354b544f8b190be1e954c7db2ddbf5e2585abd100a0e52c5f47e265c658ff35
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/vault@sha256:f963486d59f4e6885915c845325a1294440ae196f583d60aa5e174519ef8c785
SPDX SBOMhttps://spdx.dev/Documentdhi.io/vault@sha256:d56ede2d6c5c83ead6b0bc913206c85d56b8d4648e395e8c70b436cf9ceec186