Sign inSign up
Vault

dhi.io/vault

Vault 2.x (compat)

CIS
linux/amd64
debian 13
Tags:

2-compat, 2-debian-compat, 2-debian13-compat, 2.1-compat, 2.1-debian-compat, 2.1-debian13-compat, 2.1.2-compat, 2.1.2-debian-compat, 2.1.2-debian13-compat

Index digest:

sha256:f613eacb7d1ec8eeeede5a0a5b4237c32fe2be5f2b063a1e24260d5a76a5e877

Manifest digest:

sha256:cb3d7ebc435db6f58a15185f783c350056377c04975ff22d627f24a58daca713

Size

91.72 MB

Last pushed

16 hours ago

Vulnerabilities

4
10
5
2
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/vault:2-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/vault:2-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/vault@sha256:3b9d5b242f77cacabb0194a63170f569ae1af317d3b8256d36672d873b0bb37e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/vault@sha256:4d0b83dafa180c26109810408f5e709f12ca2c66a84b4da99836480589bc1a43
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/vault@sha256:56d29efe29d9aaa700fdc3346947be8ca702ce18365148bc6e51c4578d09a507
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/vault@sha256:67f70fd772a23dbee24d7e3b1908148923277b3925840a423f02a8ad0995876f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/vault@sha256:359e340a35e1fcd28c5135568cfcedc48f3d3cb0e725d49ff622c76918df96a5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/vault@sha256:a412c784381259e5f13e9f58db77d2b6e5e0b59ccd6baa19d873bc108c949f65
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/vault@sha256:1c28b8b6b94121e70445b9b12eb8e86b88620c0bb1a7ca5bdb9db8322a5997fd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/vault@sha256:e8d966d2e00d31afda83b242239bbcf70f5512839630d85f8fe19233edf74f89
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/vault@sha256:7ac491e66ee32d23a75a49760b94f9a233a9bb405871db1e449b98f9f063e9d0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/vault@sha256:5d56554b179e2ccd2b37a5f6b48b0bafbfdf233f91d21e2901d785597fd881c1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/vault@sha256:984e0a361519e3143bdacc60658309ada7839f46aba2bd11d534fcc5c98e6ea9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/vault@sha256:6c2b545479abac876465ff8f6e06bbe6dcc94a7dc5bdc8463ff26a2943697f31
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/vault@sha256:c769ad34110f4198c94fd56f203b087ccd3f5d09848184b87896572c1323b29a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/vault@sha256:73d0a837cb79926641267a7e407918276a212d3b22501284ccd228c0cb5d8e91
SPDX SBOMhttps://spdx.dev/Documentdhi.io/vault@sha256:0b51a329c9040f44f61c5d36e5c131e76485870485bec46f88612dd2c644dce5