Sign inSign up
Vault

dhi.io/vault

Vault 2.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.1, 2.1-debian, 2.1-debian13, 2.1.0, 2.1.0-debian, 2.1.0-debian13

Index digest:

sha256:0b65a5e25083d85b70d6fc39881bdcb5c4b982af6819a091a53fd97c113ed1a5

Manifest digest:

sha256:eddf1661f99c9dcd52c28d82ba44903de43c86c00971303c09197c02638b24a3

Size

82.58 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/vault:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/vault:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/vault@sha256:49e0ae2690f6aef50082e3647e40867aad8750c79ba5531d2c86eea8df3ba413
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/vault@sha256:4cb0499b6c9c885304f0e04aaa887910368edd45a0c814de9fb1ec26449e77d2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/vault@sha256:493a8906f04f6d41c992b37a56bc58d5b11e968e372d7f9c776a041352916cc6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/vault@sha256:e6e5badeabe2c5c8667a86c5e680e2131233394a6c233045816e576d76afc673
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/vault@sha256:b1a081e1d3aa2c6afdc5dbed97c9dd340d1ed4619e780f4887308b802727c249
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/vault@sha256:fc2ad4fffb5fbaae0b93e092c3c99614322c049e2208c37a5d0c7eea1ca4cd6b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/vault@sha256:d40391e73aecc37576aea88ad29432bde9fb30c6e27875b561bf6de86c683cc2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/vault@sha256:1d849a218f8ca69f49e3be95af4b78d866dba4b1729073eb57adbc2a866e0856
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/vault@sha256:9d4fe1988fdbf3470b967ea299af1bec9e9a5234ac151d6cd7f821b18263d66d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/vault@sha256:ae10c879f2e7e6fb2ca5620fa382c374e21a1bd2e48b99723029995f551583c2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/vault@sha256:8a1c0d837a06cd1d62a2719b45a2c63f36dacf5bb9581ae77e47d57a489d67b2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/vault@sha256:a6feb92f7d794930f0e3ae3ac4200df4bc960aaa5cfb87b4a04437d56dda1fff
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/vault@sha256:d63ffed256ed1eb884ec9929ebfa9d8372c06db6e9801b7852494dd338c115cc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/vault@sha256:7e7de46c4ab8ccef67ea74f0c61907c5a8f9e4a57943f2a4c38c83e79ff8271a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/vault@sha256:255487582660eeec0de567685ed385a7bdd53cfda48d20fd52a92d03d301171b