Sign inSign up
Vault

dhi.io/vault

Vault 2.x (compat)

CIS
linux/amd64
debian 13
Tags:

2-compat, 2-debian-compat, 2-debian13-compat, 2.1-compat, 2.1-debian-compat, 2.1-debian13-compat, 2.1.2-compat, 2.1.2-debian-compat, 2.1.2-debian13-compat

Index digest:

sha256:d5d86d87ec01abb374827208b1029cccf88027eae89218d3cf3a04be8b906d97

Manifest digest:

sha256:5608529f779c409fdf577d00c63ec7c503739b6a5f405f6bc09be40a85900363

Size

91.71 MB

Last pushed

1 day ago

Vulnerabilities

2
2
5
2
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/vault:2-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/vault:2-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/vault@sha256:0d40cd09097f1da5bb5ff54b2317b6f965c51ba82cb9626d54480394e5098884
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/vault@sha256:3f6d6aea11064a901b651d03c47dea07626ac093fb1e789f4aa44f541e7b71e7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/vault@sha256:e812b285263c60eb976bcb6bf4842f448284c878903c37ae7874315161be7665
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/vault@sha256:15c6e5f3289813aaca2b05a52418c8db02becc9d5695cb657ba8e16eb97b890a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/vault@sha256:89d8e9d3f8ff0e4de79f48ad86b6458d7fb637b6105170794087e427b9f24db4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/vault@sha256:0fc1f20c23d66235bcc9039d2fb5e01b25666afa39234c8febc18d3d5ec0b64a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/vault@sha256:1d16634f8b34d9b23399b78b2b41884861e4a2686d3d2469b0d46b154511a602
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/vault@sha256:dbcc8187a6700f29fd365cfe264028a02ec42f4c4b55c878f94ea8704176991c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/vault@sha256:f474e430990281ae8fe80b019f61261e902af092faf5f891b57187a7f19473f1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/vault@sha256:4cddcfea7719e3f56a72ff10273f5bce69f0573237cf24b71886fad5a9273854
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/vault@sha256:6882c045d46f58c4c58d3c2b006a54cf2ee03ed291d45e3818a2873bcaf37838
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/vault@sha256:23a645b8b345cd267c26a004a9dd1b4e559023b29afc608bdc3b2ec7df22fa62
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/vault@sha256:0f857268e1aa2a520bfda8d284cbb5850996b7dbf6a4e1a8ff9d84ded8884541
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/vault@sha256:f0842d21b7b47f0da3af0da22a0868d4a6892e505db0797b2bf6d8f16b915aed
SPDX SBOMhttps://spdx.dev/Documentdhi.io/vault@sha256:e5300bd87b69a482b92e89a8a387e00d7d8e724d0f72cdcfff265feaa523eb7f