Sign inSign up
Vault

dhi.io/vault

Vault 2.x (compat, fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-compat-fips-dev, 2-debian-compat-fips-dev, 2-debian13-compat-fips-dev, 2.1-compat-fips-dev, 2.1-debian-compat-fips-dev, 2.1-debian13-compat-fips-dev, 2.1.1-compat-fips-dev, 2.1.1-debian-compat-fips-dev, 2.1.1-debian13-compat-fips-dev

Index digest:

sha256:da2f7cfc881dacb7f45fc48e41a16f520525df21f03d3c5e8a63a367b14fa402

Manifest digest:

sha256:5ed5643b854b8d4b238071d68483a39b7d4fa5b317c7413233bcc72c4b052398

Size

179.34 MB

Last pushed

3 hours ago

Vulnerabilities

0
4
4
4
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/vault:2-compat-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/vault:2-compat-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/vault@sha256:1a4e631505226a39456526e4d595d8ade844c41f5a2e62aa0cc81a97c6ecb5ab
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/vault@sha256:5ba3d16e3cbc12637961d64f643009f79f2d5a98344e4fcb74aa6a9164700b2b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/vault@sha256:2e9b956aa8b40c350c5fb4c71431324e6bf8a2952cab9b13b23cecdd6d722f56
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/vault@sha256:a9ac4dad9e304e72667a55db7da9c30f33c47655758a29d1a496622b6fd086c2
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/vault@sha256:04c510a52fc04c44af3bf17a5d0ce0e3b53d5129537ff397cf7b23d4ddd59916
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/vault@sha256:c67d5b9e003be870b0b989bb587a961ebfdcf9e06892ebe99782b8c1b7d9a96c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/vault@sha256:2729a6f308b4b6f6912f8d53ff76ad590ce70633b7d595658025227550187aab
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/vault@sha256:e9bdfa906ab60990065bbda9bfb9260ab8517ae68605c0b0157c6364f0f77598
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/vault@sha256:bdc6da30afa5b07d1f244b56528243e0ad3d457e879e2830ca9cc2bcf9446cd8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/vault@sha256:40f32467589f8a281253655e407063addc0a2c8750aba8f2bbafa7ffdc6117b5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/vault@sha256:78e70ee15ca9eaa5765f32a7f464f0ab2efa99a8ef6e49f91363888bccedb5b2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/vault@sha256:2d3dc23625ecd63c24d0e2f60bf1a5fdffaecdbdf9587211bc7e22a669ef4929
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/vault@sha256:1ee07b68afea47ff20418218e7baad6f5a3c115ebc6e08e0fe5702c01ca779cb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/vault@sha256:25c353a56ea7eb1bcd96216f69d020936e2cef0e7e6e7ee5917cf385bc6f4e30
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/vault@sha256:c898a3591c6e3f7cd3dba1c203087424d23a0924636a9b9411cd056491908739
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/vault@sha256:a4be40b2de4823e18080815403a4cd1372abfbebb34be42f00edc04f602d422a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/vault@sha256:9321f0f514e7ad94488dbe8c83b06898f597c5d72fe47b4498ad0898bd9da741