Sign inSign up
Vault

dhi.io/vault

Vault 2.x (helm)

CIS
linux/amd64
debian 13
Tags:

2-debian-helm, 2-debian13-helm, 2-helm, 2.1-debian-helm, 2.1-debian13-helm, 2.1-helm, 2.1.1-debian-helm, 2.1.1-debian13-helm, 2.1.1-helm

Index digest:

sha256:6c0e91614d300ce67ad2ded5667f07d9d5069492a65083478202995b03ac4e21

Manifest digest:

sha256:cd2b17c462f146667b4ef242082dc62e781ea329f6e97e28e01fec64dbeab1bc

Size

89.66 MB

Last pushed

14 hours ago

Vulnerabilities

0
2
3
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/vault:2-debian-helm

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/vault:2-debian-helm --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/vault@sha256:608addfd66b9d07400a2bf3122a5342fedffe28ff7a6704127394261419dcb36
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/vault@sha256:d217e4d9e5fae08854127e54fdcc876b65782ad69608a2e2572ecce23c1f8351
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/vault@sha256:6289ba99fc4737ab2164abc01e7ae1762dc729b11ac907b7c18aa87368a7b550
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/vault@sha256:6557ee88adffe326e37982fbc322d0478c7617d1fa2a1a8f4f321af02f511dba
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/vault@sha256:7572d00c9628618e3ab5765978076cf5ee7bff1b5d2e385d91b15bca05aae934
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/vault@sha256:ec53f7aa6a95632b47e501af6d67b3a93540bbcdcc9cc2d7efef876d3b50dd8e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/vault@sha256:3bbff8667eb0565eabe7dbd1ec6d82dd26cc3e3b30b2479103af98f55d486609
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/vault@sha256:5037548e7f659f9aa38dafd357b6d1cee39bcbc89b3e83127981a5562353349a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/vault@sha256:4f4d246cc86983859346ae1e8a8dbc129ab944a26d9c4257f5716730725e746d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/vault@sha256:50ab2cd8d03a724a6d5931bf120a6b1e04eac96224f166ed7005d6d9817876bd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/vault@sha256:9937e25e9ce2b223006b6f0b05f5db91d590a84a00cbfbdf66218def9265bc5b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/vault@sha256:4323e05715850cabb0c9387788936a41d211f1c54b6273791c4a2691d13dfd14
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/vault@sha256:45eda2365aa915608cbf7907ee3526763e4523fbb68799acce76e3976f22c9d3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/vault@sha256:5c64ae53a0515c909ca71d2e771daaec1c265685dc604854075cd10e1fce608a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/vault@sha256:62d88a2d724012eb69ed257e27b40758b898bebcbc3477ac400979b1413cf235