Sign inSign up
Vault

dhi.io/vault

Vault 2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.1-debian-fips-dev, 2.1-debian13-fips-dev, 2.1-fips-dev, 2.1.1-debian-fips-dev, 2.1.1-debian13-fips-dev, 2.1.1-fips-dev

Index digest:

sha256:099b70890e09424b74cacd2f5df0018502271d0f8f138910fc256134aac5da20

Manifest digest:

sha256:92a6d5ddb0375275d51d58cf93cbdef12cb92547c2ee659fb2d0c00901a54fc3

Size

178.12 MB

Last pushed

13 hours ago

Vulnerabilities

0
4
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/vault:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/vault:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/vault@sha256:62176ff97254bc5372bb3a447126a9857e54f83bc97cadbcd2ffd9a88101bb97
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/vault@sha256:a66dd431cb57c26e650b4b95c4e64e152d63f1186a05997a865023f958213801
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/vault@sha256:d8cea1fada797a6bb73a316ce72318af1acf9ae85af353263aaea7a2984ba411
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/vault@sha256:a1fa7bb13142fdfb5f08bdaebf92d14bb26f42a1220aa12055d7a41f7d8216f8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/vault@sha256:5bc05f58cd3cff5abd526e4f8d4e7b96f9630adcce0520ec6e1d834af4bbd86f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/vault@sha256:8ee9c73ea02c108aac0c5dfabefe1c282bf64effeb3b158725e8194ca87635ae
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/vault@sha256:670f5c98f4e3318d1919e24b66c66d46c88dc0f05cb2051a26b8ae005756f610
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/vault@sha256:e42dd84b2ececa9c57435f8de0e9faf89c27f1803b3160a73e8ed838f54a865f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/vault@sha256:f1b39fa90f689fa708d7334f96398a3d6e0e8e3197b52fc75e4b2ad9d3a9c697
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/vault@sha256:e206750454bc3b7c933b8213eb718632d5f8e1fb7b49627176858623554b85d1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/vault@sha256:791ab718691e9a125c0e4196c249f84b9402c533903d7d58c89bf825c33e5fee
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/vault@sha256:66a5f1bf6077f6cf3d2c6594dea91c8162db225844d1b2201d833f34eb39f980
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/vault@sha256:491ee16119d7d049998f728c5e4571145b001cf1067d2237c5d3b240c6ff9883
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/vault@sha256:e13daa625caf952bd3d3e43b37015aa995aca216edf9a948eb47f6dc05f23b0d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/vault@sha256:88bd27499359adfd421795caa1877386b898bc2886ad45725dd1da3a25f97db2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/vault@sha256:d3492c5af3d6cfa57ceea8c6cd376868651e04ada8f2b1e776c721fc6de20d48
SPDX SBOMhttps://spdx.dev/Documentdhi.io/vault@sha256:e174864919ea3db74a6f3b6cf68199a073fd0093346b0b6cdc969130fac9657e