Sign inSign up
Vault

dhi.io/vault

Vault 2.x (compat, fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-compat-fips-dev, 2-debian-compat-fips-dev, 2-debian13-compat-fips-dev, 2.1-compat-fips-dev, 2.1-debian-compat-fips-dev, 2.1-debian13-compat-fips-dev, 2.1.1-compat-fips-dev, 2.1.1-debian-compat-fips-dev, 2.1.1-debian13-compat-fips-dev

Index digest:

sha256:0b4c0020fda4be1c3c0acc1fe20241b8f8420bc56043113f9a1dc20aa8ebfeca

Manifest digest:

sha256:9a339b6c5ae593c911593464c95eb423832c9d37b91b6fbebb831006b0a38d2b

Size

179.36 MB

Last pushed

17 hours ago

Vulnerabilities

0
2
3
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/vault:2-compat-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/vault:2-compat-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/vault@sha256:ffd8db6797722e08bd45b46d267472d8f695dbd95f48d1ce9e046f24302fa723
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/vault@sha256:fc4d2808a582e0e477c2b4b7f1b1bdb8a3e31b408c1cdc8bd759f993d3a64c37
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/vault@sha256:78ce060234daa4fcfd485f6d04f7956162dd5e7ef92a5fdf455a685584b582d5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/vault@sha256:a1d628ad2a45c36bae32502fc2e013c1a0a36e1dcfd5cbdaad65e51ff0eaae75
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/vault@sha256:fba819a6a26f9c071ef4daf77821b10f27cc1f5d8ab286368054dd03dec62464
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/vault@sha256:c9de5143d1d5e39a4164e92e4841f2328aed1c377d91e46a06a4265e45d4a0db
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/vault@sha256:3fef43e5cf3f862f435fe5b82c28dbe1e8aecadf1c8aad1e6302e576e280cb43
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/vault@sha256:3acc0f2b48033eb8ca6d1a8d803b2cd4d655fdf39c9c77b92578bfdf4972a3f8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/vault@sha256:f1f03c2d81da2dd24231a2b02dd91935c7c1cb000ac139f2f6e97e5fc62b263c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/vault@sha256:9e0644e7ec724e2296aef2785a70932f0c2f658258be6c74fd4646993f6abc26
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/vault@sha256:5203bd3dca224874d20cdb9d1b3380a3ba4e5cea360ad8b02a4c7c83506218f6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/vault@sha256:b6bd8eabc13f19f6e417f3fee7cbe1505e98b0b15441bf656ec35fd0c0b8fa4d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/vault@sha256:ae36dda547f2d1f9c3b2c6d7430e47450b1688594457f1831aed533ff357582b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/vault@sha256:232d7072644e2d5748a4042256ffed4ad4a0921a23158481fbc37a0ad73c8751
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/vault@sha256:489037c5ca1504816aed61e196afb4a98d2af8beaf6c947812da30e02c9daa78
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/vault@sha256:d76a4461792b0be0c547189c69e982c1488421c213410695eb71126e84e9a89b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/vault@sha256:8074cf36817409d289a7f9fb8ea65fa2ebff0f2fef9db9d508b427ad8d070418