dhi.io/vault
2-debian-dev, 2-debian13-dev, 2-dev, 2.1-debian-dev, 2.1-debian13-dev, 2.1-dev, 2.1.1-debian-dev, 2.1.1-debian13-dev, 2.1.1-dev
sha256:9c8fbcdf31914e076432dd133441ac9b616d831f039c2d95d370a6ee1a09fa9f
Manifest digest:sha256:f511e583fd1bbe0167a74bad30e827408c05af4e0066459caeec7979e21b7cfe
Size
177.49 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/vault:2-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/vault:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/vault@sha256:3b2a3994f9aae2dcdb3d93fb55f43952c7217b5a9df09d28b3ee33ad1ba1b40a |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/vault@sha256:494b6b1fafde89ff28b57bd6d9f3875cc2d951747600e200e6bd64f3a1cac4ce |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/vault@sha256:df2961a976797c74cf5399696a3e8a20e6a6b1367d6eb5b2891274ad366664ea |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/vault@sha256:086950e24d48d4a6d361873d42daecd14b53d46c6c8a964059e25325a0062dd9 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/vault@sha256:ed8b75e9244317134643dded1f72b075370103760a8f1cdda38a73cfe5cdbac3 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/vault@sha256:83194015e27d281b67ea00d14027fc96ae63d58b1f5d3e53374a13aa73218e15 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/vault@sha256:b5ef5e692e799983c1ccef0e20b5b79309468d52caf0c9d91c12253f7c35c2b1 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/vault@sha256:e9d0e6daeb597c32e62c7e13629e7017b39f713f6a31b8d89096ce9eec7a9d17 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/vault@sha256:9ad56ca447ff5f5b1f80f5173ec604fbaaca078c4dcee4a3bee3d544b6f4496a |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/vault@sha256:41fae59751b2c96539daec930c26a9216190f5cf991553a957248c783b9a7ef8 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/vault@sha256:7d94cbba5c28c85a7ec44cc643b606e31957ae6eb0dc771960b6f9583bf432f1 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/vault@sha256:a1c5ef224de01073bb35d4a4d3a757462cbe0019f2c5b292009afa38f53096d7 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/vault@sha256:9d788946cd62f75cd104f53a345e33b524203a80c59cd6fd76b371fad107fd59 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/vault@sha256:e2cbfe4096c62ae184139dc2a7a4039b01e74e6d03ca1bf448b80b9cfd1199c1 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/vault@sha256:06b71c113c72fd1f12ed0113d21116814c738af422a7b9749b421a3eb8ec08af |