dhi.io/vault
2-debian-helm-fips, 2-debian13-helm-fips, 2-helm-fips, 2.1-debian-helm-fips, 2.1-debian13-helm-fips, 2.1-helm-fips, 2.1.0-debian-helm-fips, 2.1.0-debian13-helm-fips, 2.1.0-helm-fips
sha256:eeeaca267a0c2614122bd37215b139405c95ac808675830236dff97a9c0f54b5
Manifest digest:sha256:d860ad6b038bb853be507cadd67a1452833ed24aaa227a88a22422f7ecf32ffe
Size
91.54 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/vault:2-debian-helm-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/vault:2-debian-helm-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/vault@sha256:926756b8a61682f7c289955cce5a5b4848950d7ab527403b4cdcb890436bc734 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/vault@sha256:7c3d99c3a245d71be6c334f348bd4b668a0a7eba2ed3789ebc3f4855bb766ede |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/vault@sha256:0aa6ade0ee84b4989c3c4f829d201e9e5493a0942e8e523e87b4e154d4081ca4 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/vault@sha256:e12cc7b999c7dd1e034b68eb627a7f03d8a77a389ad1be237217c2a304d23f10 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/vault@sha256:16f3969e09da22232d9b1eccbc0a5bc5a1a8f744d9d685fdfb2659b887461349 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/vault@sha256:9234e40e1d672b3bf15bf40662f33de350806ceeed1478dc8f8091eabdc19659 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/vault@sha256:4461c0d251a350fc7f92de0eebcf38815bd0bca782c77f87fdffeea6c2995903 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/vault@sha256:a6a9667b7df2b4eb98ce2db82fb3ae5e72012e25f081eedc4217ae1550070aeb |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/vault@sha256:4fad93a4c1946895a00768645a6fa62cb66c0fe9c23162bfc39bd010fef0977e |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/vault@sha256:e8e7f55a04790cfa8efe7dce1d7dd2e33a1bea5bacaeca863109265c5783f58f |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/vault@sha256:99664efedec74d8819db4c8a4cf9682403ce7bb20c1ebdea79cdc46c381fc4b2 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/vault@sha256:845e358ba84e8ec268bb8bd7a8f2266abe8b9fa2e0a8b0b0c5e9aabe365eb518 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/vault@sha256:052986e50e28fa6b0d666907a43ac5928688226af8253a88b0454ae5e341683a |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/vault@sha256:e12ebeba5e00e377d0a4887d0fc9039b2861d295782668c0b853b0f56bc5a22c |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/vault@sha256:def5a50fa20cd3ba29d80537764a40a5ffd9330d6210edb2570e4d5968bb2b57 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/vault@sha256:5c87b1b52f044034e270eb785677a7c7f814d93b411e3bbb58743dceedeb5124 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/vault@sha256:e277c476d82ef47f511b6ce2185118a4950040a4b053cc9b55666991304d4e34 |