dhi.io/vault
2, 2-debian, 2-debian13, 2.1, 2.1-debian, 2.1-debian13, 2.1.1, 2.1.1-debian, 2.1.1-debian13
sha256:05481ed4203746104b1a63d9b314e2b6eaebe35f836d910fad435495460fa7e9
Manifest digest:sha256:a3fd95d872556e27d9771b8f1d37a367e65a35265145348d155ffd121c9ca669
Size
82.91 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/vault:22. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/vault:2 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/vault@sha256:79f1dd71b0973759ff19c1dd69a0c53dbd136eea30b63cb2d5b10f7cc0736608 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/vault@sha256:440ffbff5511f40bc93604a69e46196c4940d0cdc4a12f206c2b746fd8c76e6a |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/vault@sha256:c0f4a6423558ca47769a2ae5bcbd5688d7d28396989b6b6ecc9d35078276349b |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/vault@sha256:d38bc19d0bf72d5d801c3ce95408fb0d5667caa63146df12f5f626eadfb50a2b |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/vault@sha256:1cb6952e5fe457fd56d2a0503da8525fb25e20ef6f8067bf475db10ba47ec080 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/vault@sha256:86f2dfa1e4bef2e68950e8e14f9e9b9b27c0f92ae197c2cdaccd4a52eedbc692 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/vault@sha256:c960868b47a50fa0511e31b18ecee043bdc8bcb5d98495ee8d09dbe1a84d0297 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/vault@sha256:ac1b3a58a5137e5716be985f6813994008673240669f6258515c4c4177647d25 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/vault@sha256:3a3df2134336da9bff236c5c837aaafbf5c059f2212e9ed9a61c359376bb5cb7 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/vault@sha256:a782b7dd41b105cd64c4a023a56e2f61c49a35c8ec36ba8abed8306c8540240d |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/vault@sha256:e14c1ef730408d752c2245bf67c0ed5500ab93b96f6ecde5650ecb6329f17c4d |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/vault@sha256:efdd41921d8f7235cb03b2d87a5e1a250c06d79b64acc30585b6c77c53d4fbea |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/vault@sha256:377104dff71eb3757cdb81e043819984655b8054ecf3fc9dcef740c6f09b4eeb |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/vault@sha256:f8d07d9d9777c3e9da901b803750fda2dc115552bcfe7dee2de39372287c30d8 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/vault@sha256:b95aa384e4f9178bdaf1c26ee21fa873ee8e94304ebf565a549103a0bc03babe |