Sign inSign up
Vault

dhi.io/vault

Vault 2.x (compat, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-compat-fips, 2-debian-compat-fips, 2-debian13-compat-fips, 2.1-compat-fips, 2.1-debian-compat-fips, 2.1-debian13-compat-fips, 2.1.2-compat-fips, 2.1.2-debian-compat-fips, 2.1.2-debian13-compat-fips

Index digest:

sha256:c4dbfc971d341dc6370d26770b2967be268d963fde1c67f046e4d096f172418c

Manifest digest:

sha256:80da49b58ec839f4022193122b27373dbd03591785492299f10f288a8ac2dd31

Size

93.95 MB

Last pushed

15 hours ago

Vulnerabilities

4
10
5
2
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/vault:2-compat-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/vault:2-compat-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/vault@sha256:8a4f585e652a97186c71820bec7f1df61608e4c76984fa7600fde62b295c7f4c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/vault@sha256:070ff9ada4965b66bba54247b122d4b5cf50dcdd906ea8aeea6596373d97d37d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/vault@sha256:b46be24dbb6dfad6be7145c92e5cfd767bcfdd7a0742be6fc4a5bb2962d54b73
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/vault@sha256:7353324d037d044787265bc01d6c9d90e79d384fca6c55ffb8727d93cf8430d3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/vault@sha256:920f88a81d67e59c3b586fdfe42d39d062988b76cf10c18a0c2a8eb57eef1f24
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/vault@sha256:68a1c65042a10e6d200c9f3a04daa48585c0373d164074a7fb2942153d8c7643
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/vault@sha256:101dd8ef6e98250065ee90be685781e8acf37558c93267336e24b7d68a2541fc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/vault@sha256:b99806a148695207a63f7afd89b1f748529db067208d68587883f1667bb7bc3c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/vault@sha256:6b04715849c73a0e75e7a605dcb3bbfac7d97ca22fc425e38ec574dcea1c61cb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/vault@sha256:81e32a570fc4b2558367f8aa6f43434f4a54de3bd125ede9afe98109b958e322
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/vault@sha256:acd631eb3a11c26e5a80d9561f6b0f1c48b717ef236d6e48ad76a12989312ecd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/vault@sha256:312362bd05f3e5087e8c8f6baf384c3c6c51909c5ba79b996dab4c023d0dfc1b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/vault@sha256:146eb0788d8a066eb9a2dd765631a8a60d1ee6f89be441acb7e66a60045274a1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/vault@sha256:1dcbdc72d5c0751c993c668754726b1541fa82f30d14f3a157332161bf09a1ed
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/vault@sha256:ac591ffe6daa3f2f52dcd5b8b96dd784da6f841a837629337f4d802debd4c1a4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/vault@sha256:db7bf812cdefca3175b56884c3a8ed8b474bed06edefae43b1990d0f2e85e1eb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/vault@sha256:df56a0b0851812a811af240332343601b26979ea0690c28e05eed1a376803822