dhi.io/vault
2-compat-fips-dev, 2-debian-compat-fips-dev, 2-debian13-compat-fips-dev, 2.1-compat-fips-dev, 2.1-debian-compat-fips-dev, 2.1-debian13-compat-fips-dev, 2.1.1-compat-fips-dev, 2.1.1-debian-compat-fips-dev, 2.1.1-debian13-compat-fips-dev
sha256:0919f37be1886c35543f6d37e472b6f3eb1ca32bf66bfdbacf90dc27a1f44249
Manifest digest:sha256:eba830656d08bb9825f8cff97b9780b048daeaab7d5cd770483f5929d54ff085
Size
179.35 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/vault:2-compat-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/vault:2-compat-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/vault@sha256:17b3ec5ca64cb4a0f1ca6c2c4eb038a15e9785055a08d6e40165b1da9143889b |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/vault@sha256:f7c5c40e752e02e907a755dd01bc37989d45cc459969e3503a1f6f9cb579adb3 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/vault@sha256:0c734c90dd54c15c6b43a4c971518082cb6abc04f1e57fc7b234d7e8e50021ee |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/vault@sha256:a4dcb82b93f19191cb1d0ef4f868e8a5f9889471e35525ec095a777a8f8ca593 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/vault@sha256:28dcd7e3af5cc728034cbacf9bc1b5f33ac11dc8bc04affbc16a2e5e756e45da |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/vault@sha256:5088ba62326c43c3471a1ce80c663a127af9f61b25a834b1f8e5ebe98867419f |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/vault@sha256:186ad11d63dd4d73e1e9636e8bee741fc12bd3353ceaba28fee8d36689b2cbad |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/vault@sha256:a6fd97c3246a446f8f8762c21cbc941e5cac4e5e7f5d145e24af3265b2eb6bff |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/vault@sha256:75dd149c10eb65b5b351974c86a1b370c742a91e57628da0f6f4410e8ba02316 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/vault@sha256:031e90ee95d5df42ef946bf0731aa52475305ea3985449143dade1de7ba4a1bf |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/vault@sha256:9ad33dc16b57d456de01f941e45cdfab4631eb0ed57b772819ac59442bfd2bca |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/vault@sha256:d5bca8ff6921b46cb1684eb972d0eba9f43528153f4c2f98795cd62c51cd2e26 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/vault@sha256:46d218bf8faecf804b1d9c0b22337675be1b87e450a18eca2a12a5d49d47a28b |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/vault@sha256:2b713af2097338464b499270d700c290e2ad5b99485c8c7685bea1128f89b245 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/vault@sha256:38e5bb519e28e63583f802e272ba2edbbb6a273c162d4bd6dc661a08dceb6327 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/vault@sha256:4f12d757051ee6891edbf511815de31abe55f5cbf7b7905858294139ef217c32 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/vault@sha256:5accd197c1033b096f653e30bbde2f9e0f1e738b068eb83870888f622aa872c9 |