Sign inSign up
Vault

dhi.io/vault

Vault 2.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.1, 2.1-debian, 2.1-debian13, 2.1.1, 2.1.1-debian, 2.1.1-debian13

Index digest:

sha256:05481ed4203746104b1a63d9b314e2b6eaebe35f836d910fad435495460fa7e9

Manifest digest:

sha256:a3fd95d872556e27d9771b8f1d37a367e65a35265145348d155ffd121c9ca669

Size

82.91 MB

Last pushed

2 days ago

Vulnerabilities

0
3
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/vault:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/vault:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/vault@sha256:79f1dd71b0973759ff19c1dd69a0c53dbd136eea30b63cb2d5b10f7cc0736608
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/vault@sha256:440ffbff5511f40bc93604a69e46196c4940d0cdc4a12f206c2b746fd8c76e6a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/vault@sha256:c0f4a6423558ca47769a2ae5bcbd5688d7d28396989b6b6ecc9d35078276349b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/vault@sha256:d38bc19d0bf72d5d801c3ce95408fb0d5667caa63146df12f5f626eadfb50a2b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/vault@sha256:1cb6952e5fe457fd56d2a0503da8525fb25e20ef6f8067bf475db10ba47ec080
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/vault@sha256:86f2dfa1e4bef2e68950e8e14f9e9b9b27c0f92ae197c2cdaccd4a52eedbc692
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/vault@sha256:c960868b47a50fa0511e31b18ecee043bdc8bcb5d98495ee8d09dbe1a84d0297
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/vault@sha256:ac1b3a58a5137e5716be985f6813994008673240669f6258515c4c4177647d25
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/vault@sha256:3a3df2134336da9bff236c5c837aaafbf5c059f2212e9ed9a61c359376bb5cb7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/vault@sha256:a782b7dd41b105cd64c4a023a56e2f61c49a35c8ec36ba8abed8306c8540240d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/vault@sha256:e14c1ef730408d752c2245bf67c0ed5500ab93b96f6ecde5650ecb6329f17c4d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/vault@sha256:efdd41921d8f7235cb03b2d87a5e1a250c06d79b64acc30585b6c77c53d4fbea
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/vault@sha256:377104dff71eb3757cdb81e043819984655b8054ecf3fc9dcef740c6f09b4eeb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/vault@sha256:f8d07d9d9777c3e9da901b803750fda2dc115552bcfe7dee2de39372287c30d8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/vault@sha256:b95aa384e4f9178bdaf1c26ee21fa873ee8e94304ebf565a549103a0bc03babe