Sign inSign up
Vault

dhi.io/vault

Vault 2.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.1-debian-dev, 2.1-debian13-dev, 2.1-dev, 2.1.1-debian-dev, 2.1.1-debian13-dev, 2.1.1-dev

Index digest:

sha256:9c8fbcdf31914e076432dd133441ac9b616d831f039c2d95d370a6ee1a09fa9f

Manifest digest:

sha256:f511e583fd1bbe0167a74bad30e827408c05af4e0066459caeec7979e21b7cfe

Size

177.49 MB

Last pushed

6 hours ago

Vulnerabilities

0
3
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/vault:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/vault:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/vault@sha256:3b2a3994f9aae2dcdb3d93fb55f43952c7217b5a9df09d28b3ee33ad1ba1b40a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/vault@sha256:494b6b1fafde89ff28b57bd6d9f3875cc2d951747600e200e6bd64f3a1cac4ce
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/vault@sha256:df2961a976797c74cf5399696a3e8a20e6a6b1367d6eb5b2891274ad366664ea
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/vault@sha256:086950e24d48d4a6d361873d42daecd14b53d46c6c8a964059e25325a0062dd9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/vault@sha256:ed8b75e9244317134643dded1f72b075370103760a8f1cdda38a73cfe5cdbac3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/vault@sha256:83194015e27d281b67ea00d14027fc96ae63d58b1f5d3e53374a13aa73218e15
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/vault@sha256:b5ef5e692e799983c1ccef0e20b5b79309468d52caf0c9d91c12253f7c35c2b1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/vault@sha256:e9d0e6daeb597c32e62c7e13629e7017b39f713f6a31b8d89096ce9eec7a9d17
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/vault@sha256:9ad56ca447ff5f5b1f80f5173ec604fbaaca078c4dcee4a3bee3d544b6f4496a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/vault@sha256:41fae59751b2c96539daec930c26a9216190f5cf991553a957248c783b9a7ef8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/vault@sha256:7d94cbba5c28c85a7ec44cc643b606e31957ae6eb0dc771960b6f9583bf432f1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/vault@sha256:a1c5ef224de01073bb35d4a4d3a757462cbe0019f2c5b292009afa38f53096d7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/vault@sha256:9d788946cd62f75cd104f53a345e33b524203a80c59cd6fd76b371fad107fd59
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/vault@sha256:e2cbfe4096c62ae184139dc2a7a4039b01e74e6d03ca1bf448b80b9cfd1199c1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/vault@sha256:06b71c113c72fd1f12ed0113d21116814c738af422a7b9749b421a3eb8ec08af