Sign inSign up
Vault

dhi.io/vault

Vault 2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.1-debian-fips-dev, 2.1-debian13-fips-dev, 2.1-fips-dev, 2.1.0-debian-fips-dev, 2.1.0-debian13-fips-dev, 2.1.0-fips-dev

Index digest:

sha256:35c6abb36c958fdd7e9b2cc1be400fad088b1af1cd2b4528fe0d883038a8a7f0

Manifest digest:

sha256:eeeb8e30e7a2d228b544dcba6d710ade2f677e4a6f789f9d694f274d397d5907

Size

177.48 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/vault:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/vault:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/vault@sha256:91aad0104448d5b8e893be5d15d7041c806a62506d40ecfe86797bcf882547db
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/vault@sha256:51f8bb7c4623aefb020f886047eef702ea8deede07518fe0da805efc4b4c32f0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/vault@sha256:709e5f46cba11541b6f84374bc22bdff1b27213651e196405c3cad5b1aca4170
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/vault@sha256:b2249203f3d08065548264d42533cca89a58698e51d4deb5798aa5f39b9255a9
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/vault@sha256:f0cfed66181119ce5260ae266b7bf189e136d9836ebf62fd183253e7afb001b7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/vault@sha256:5efe51a2f8bfd3ab0713296acd04bef74a63e019c495d009d0336ac342f55cbd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/vault@sha256:1fdd972352205c30c7a2626fea92c2cab77301da335397c76a3ca442420aabad
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/vault@sha256:62ed3a3a07b3280c8430318eecd78d928e4763df1e74d45a4770ca847ea87da3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/vault@sha256:2b57a40e982c018b28ee3dc736d8b8c1d0f1c68f1ce83a4964abfc0c6f448512
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/vault@sha256:ffbfb09bfc10a23e71af34a3585bc23fca94fff647e435932f615572aa9c12d0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/vault@sha256:5fa55a1201aede11fc5c973506785fca33363b3929970d22e962e6dfc5e96500
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/vault@sha256:558acbd4e1acb642b1b0380866c9ca58a2fa7860737f9906401521dd91ea360e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/vault@sha256:fd1bf19b1154915901f8fae73ac2090df2f004625d70b7557802d7c6d839930d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/vault@sha256:bb4d294a51b1f390cd016de0059e13b64e6fb9babd70e344ebc83eacfdd61a8b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/vault@sha256:c27fa64e93f4762e57b440ae5ee9fa7f1995d9e088310fc52e81570442de11ea
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/vault@sha256:19efae3ca92d4ceb7d75ed4122f4138fd704008cc347fd4f7559dc6dccbd3bed
SPDX SBOMhttps://spdx.dev/Documentdhi.io/vault@sha256:3579ad42a8251b026f488037f239c2d2293412da3a2c5b12f1734239777f6c0c