Sign inSign up
Vault

dhi.io/vault

Vault 2.x (compat, dev)

CIS
linux/amd64
debian 13
Tags:

2-compat-dev, 2-debian-compat-dev, 2-debian13-compat-dev, 2.1-compat-dev, 2.1-debian-compat-dev, 2.1-debian13-compat-dev, 2.1.2-compat-dev, 2.1.2-debian-compat-dev, 2.1.2-debian13-compat-dev

Index digest:

sha256:a5417f05b95a122db3db7c36613e1443014fa43215a482bdc503314acaa2c338

Manifest digest:

sha256:56a2c1bae0e912b8f387bd464cc0d030adc2489b83da42423889a774a26cf581

Size

179.73 MB

Last pushed

12 hours ago

Vulnerabilities

0
2
3
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/vault:2-compat-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/vault:2-compat-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/vault@sha256:932e0bae320b59ab01575c42d065831f1b6a51e2ac6aef07fe542e963dd83915
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/vault@sha256:7218864348e5f453dd1eec1757fba0f32a2aa1ad7a5235f116393218deb06fa9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/vault@sha256:709d2fc4676b30f2236a3a0855d7eadd161f563ecc94bac87915b30fbe9a14fb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/vault@sha256:41fa58d669c4f6258a820f9801c3abce47f77b01ba571361559235078b0200dd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/vault@sha256:1a0419fddcfb1a3aeda10e3e4341a986044ee191ceeb2d9a2764ce2e99658e71
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/vault@sha256:fdd89c4a7440b7cfa3d1a2be18efb4fb82cc564d94e9a6fbe23809c11e7e309f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/vault@sha256:7b99f841c07e1b0a84f85516e215fd8424521982168213856d307b0081abf865
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/vault@sha256:679763c6600c88ea504cfa300b6dbf1b9f997b930280571779fe864e02c68d20
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/vault@sha256:a45046493b6df8ac0d913e0be08abf81c5d9bcb660f17b6a58d8d82f54b34759
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/vault@sha256:957110d860b50beb6f9ee9c0fd0650d883845717481cad07847ac60d86c6b0d9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/vault@sha256:e53b19841300945e6a7e74b9424d102b7c7db4ffc277975e8f1da3dad3353c2c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/vault@sha256:596ba6fa4ace0addc042ed45a8ce6a99bc8b423c210c9ca62695c297ef2467df
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/vault@sha256:ee0c8088df477c725b370d5780919f879b69138b92d9859b9fe9573efb20053b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/vault@sha256:3b7cb1762fccd4baeed5810f44cbcc51cc17fe93145bd26ec32c3c8d41e25ba8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/vault@sha256:0bc27fdef65e38c8df70b479620f5c445924ddfdb6d595939c4650eb96a7a5d4