dhi.io/vault
2-compat-fips-dev, 2-debian-compat-fips-dev, 2-debian13-compat-fips-dev, 2.1-compat-fips-dev, 2.1-debian-compat-fips-dev, 2.1-debian13-compat-fips-dev, 2.1.1-compat-fips-dev, 2.1.1-debian-compat-fips-dev, 2.1.1-debian13-compat-fips-dev
sha256:f121364c3b3df9c1a5ceec7943129d2e5bab1f244da3e01a1ab983148f72000a
Manifest digest:sha256:74be5faa5ea1ba9a32b9a3fb881f2da5211ec5d819d2e5b642a8e04006c0698e
Size
179.35 MB
Last pushed
7 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/vault:2-compat-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/vault:2-compat-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/vault@sha256:171352a6340ce2beccb5d3d976cd3fdd41095514bb685ce73952eaa96f1fbba9 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/vault@sha256:deae2b5fdc796fb765fbeab846dffab5e966a4063005a8ca4545bd6c04d0616a |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/vault@sha256:5bb32b232411f70e936d913080bb25057544dfc6cd6e379b9c70a5e9328dfb3e |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/vault@sha256:13aaa8ea0caba25ee13449bcd230e58792287ccde0535e9cfcc16d9f01f20820 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/vault@sha256:73436310ff271a0a59b9a6971df0122d8743340677e305bb47133ec17cd1091e |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/vault@sha256:33d897135fcb1a4b33bca50ec06ad5cff18035808b48b20437ef07cf6e39a14c |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/vault@sha256:71a2cdf8ac04d8cfa0dae2498564bf53301edaebe3a73b6a9f11435c11e695eb |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/vault@sha256:8531df30434749c88ea9a581071da79ea35a1b145fc6d0fcdc9a4ba3a87d60fa |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/vault@sha256:98ba4645a35d1fa5061a98d63b4c632948dcd1470e4566cc89d6175980f35d93 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/vault@sha256:c5e23536d8b6c4c46fd64a4e02f5543b56130ac96c5f3d472336dab2c8938618 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/vault@sha256:724b9758479596e2c61d6e84569e6a08370874e922ee73fa95cbb0cbef9ca7f6 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/vault@sha256:3e2c8cc2cf78eef183f2f2c08f22fc041b2be756c623d4837119340cfa0b5088 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/vault@sha256:35a967aece7bbd50d0c14b8b2a539f05ee23d5dab76147a11fb38280d291aa28 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/vault@sha256:b6e3a206c584b84846cab1062f38f217c8d1374aea6e9338ef4e103b3ad78edb |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/vault@sha256:0824bc746825a32fadeec9988a771a13a177e069d9887aa3e303831922a6a25b |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/vault@sha256:016957bbaa6477468e10c8eac60ce845856b712b718de4cb07a2bb8c704ba6fb |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/vault@sha256:0491cee66197b9af663bb9aab605c2952f2363d309117aa33e55d9b7937a18ad |