Sign inSign up
Vault

dhi.io/vault

Vault 2.x (compat)

CIS
linux/amd64
debian 13
Tags:

2-compat, 2-debian-compat, 2-debian13-compat, 2.1-compat, 2.1-debian-compat, 2.1-debian13-compat, 2.1.1-compat, 2.1.1-debian-compat, 2.1.1-debian13-compat

Index digest:

sha256:c06ebfda2869e3033beb4d79e89a361dc705beddf55739c71fb6a4c3d3a28141

Manifest digest:

sha256:54ed0a70d0f0ae38fa2d75c24048bca065e57a9b1c07fbb50ded7a3f76f90c27

Size

91.18 MB

Last pushed

7 hours ago

Vulnerabilities

0
2
3
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/vault:2-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/vault:2-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/vault@sha256:02234929c69b709c527abce95663edaec261528f8654a727319e92e27d2cb74c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/vault@sha256:8d24f1445cf37d6853c2de1e55a917f227bdcdc99ff5337c904189be99b625c2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/vault@sha256:466f8d8c1cfcd3fa1210b0c6b1c7f29b1eb85703edc155e64b7bbf84d8f50f4a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/vault@sha256:b95d15858fcd44d6ccdf638f9858e46523df53ca045c41cb0d0174ea1d0f371b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/vault@sha256:1a295ece84302ef5dca7abf21278a699e562ace7397e0e83041095544c255fb3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/vault@sha256:0627af6665cda6c4b5711e99543816ed93cd3a356888a8d9b14a7ffdc3b29757
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/vault@sha256:9b8ee4418ca607403cdb1fa87bae6500f642ba5d64d6e337b5a3ca7fe5cbb8fb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/vault@sha256:5ea35953fefcaf2f68ec2acf7a1df56f6f2e7af4a9df8f8793c9b617ec86999e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/vault@sha256:6a9367f0df44aba322a6e7a2799361512ecff0e18de16d42333b18236de9828b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/vault@sha256:f60368fa3949b2711cda1cacc2209f3b055435f707d0794f9d1e81fa7977baca
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/vault@sha256:1d4700ad4f4c5d9d9d4fa05190d2f5360d91faa556ad9125bdc280a7feae2308
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/vault@sha256:b997b54d11f2b1a795fd26138d3fb4da1c8f05f8b2bb7b64f40fbf1bf3e31989
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/vault@sha256:c9b7bb62c851c0321b782a505dc341c058556f3c1ec63d67857cab87bcaffa2a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/vault@sha256:978bb1b1d730f59aa864f33bd7ce6875031fdecf226e29db5702b5c7158ea19d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/vault@sha256:5b4ebb246dd97883605c74d5cdb31fd8a7a69462e5e5610089b25978dca8afdc