Sign inSign up
Vault

dhi.io/vault

Vault 2.x (compat)

CIS
linux/amd64
debian 13
Tags:

2-compat, 2-debian-compat, 2-debian13-compat, 2.1-compat, 2.1-debian-compat, 2.1-debian13-compat, 2.1.1-compat, 2.1.1-debian-compat, 2.1.1-debian13-compat

Index digest:

sha256:72f24dff0023d8d2e980bcb1893f5504d5b80155eabb9280a9723136bf1e2b19

Manifest digest:

sha256:e3ee67043b3e727ee0bffb2e66fcb3c629b1413d18a4ddbba4b81308429972c9

Size

91.15 MB

Last pushed

10 hours ago

Vulnerabilities

0
3
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/vault:2-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/vault:2-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/vault@sha256:e63139f7b49b5dd13c8b0ed9bae6a2b001fb0169bcac2a61ea31c914434186af
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/vault@sha256:638c174ba9541300cff694c648d252fec0ad04fc1a8b7dd65472a8bf184023a3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/vault@sha256:bd5931fbec0685a3baaefc3abad3004ccb89a32f8b9eb7cb10063a73f982011f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/vault@sha256:8acf7c4ec20bba33e987351a52b9e47fc44a4b96663ca797c957d37ddacc3a3f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/vault@sha256:ca8ff47615262ceb07a6c414d079fd10d3240f0b46caeb9fb67d09e72fb76b7a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/vault@sha256:21d2d7d0879f5d51d4d284b823f89aaa1b6a25ae41a4c01d0f032c1cb72ec5d8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/vault@sha256:c86e9ec654116692698e0e49cc44a366a4f512b95591da167cb1d006ba3b1300
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/vault@sha256:31907374a45a1d251ef270bf9cb51f6e83d91f9986fda690cb9c4f7e8f525c0a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/vault@sha256:f98a5b74e73c5006f3c43400e81dca51e2237fc677b27629b0cc9560dffa129c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/vault@sha256:e930db04c08e3ed980f217b6d014bf5b955543d2591a1d6b0c903893735f93f9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/vault@sha256:bb0db5b823756bd49f9f577188bd4a305a146c4554edd4a160119add8373048b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/vault@sha256:99689215e32b511325a66d7644bc58ec60a1ebc331128740ac42732e5149672f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/vault@sha256:5555dc2921634078996a1a948e62f300368649ffe8c6dd63d8cd4c752826c62c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/vault@sha256:a13678108be9f65cd4b1d4ef3ce3413ded02422b467275a2ae9d632b7480b7aa
SPDX SBOMhttps://spdx.dev/Documentdhi.io/vault@sha256:ed4065435cc9a9b6187ff8eec4d4c38f83434c90c945cce2a28f2b3a7fa24b5a