Sign inSign up
Vault

dhi.io/vault

Vault 2.x (compat, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-compat-fips, 2-debian-compat-fips, 2-debian13-compat-fips, 2.1-compat-fips, 2.1-debian-compat-fips, 2.1-debian13-compat-fips, 2.1.2-compat-fips, 2.1.2-debian-compat-fips, 2.1.2-debian13-compat-fips

Index digest:

sha256:ca00a59fd621bda39ecb8c9b0b20cc6bbe61b52ca25fdaf6d82769cdc2de847f

Manifest digest:

sha256:819401fe8b0756a72c7f8f3d9316d5a4472da78afd9e3d07b27ddc58fddf14b1

Size

93.95 MB

Last pushed

3 hours ago

Vulnerabilities

4
10
5
2
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/vault:2-compat-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/vault:2-compat-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/vault@sha256:7b959594816db18eda168647db6807b808df9c751f7c02a2a114ce97fcd09a2f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/vault@sha256:5e2c2984f1432ec751c8d74c320a01d62865c3ec3f5591caea9f7df9080a3862
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/vault@sha256:b849ad1b2c489b3af0fba956e1c21e6960bef811a93d61a1e8dc08670a2dd4cc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/vault@sha256:d9e8d4d933835fc0f18b774e2bc96b77afd14dc4c8ce87205d86d5946c1dff35
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/vault@sha256:d5cb1589d59583dabd0c3cfedabf71272692bde4f1847fa9b23733ff9e49d0df
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/vault@sha256:da4cc8ec0960593d8c2df36b4a3024939a6699020e6584df87b687c86d587f44
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/vault@sha256:6e1b42a8fb607a0a3555f04a370bc98d72d9edf5bbcdc02d4b177f938087fad5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/vault@sha256:9ef2109bd234b6d30557b3762b1565612c5db1e071db52dd1eb53b8264b4d788
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/vault@sha256:83f8b409fd15b8f95d316811ad6858b42d09636e46aa191929ed421bd41b50a0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/vault@sha256:6fd1a4761d6929a261f6e655448c2ba6a583daa61685961aa9449617d8d977f0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/vault@sha256:a8eb9ad656275e4cbecfa7c3ca52f99cbfb534958e9c3e2041a541759f520fc3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/vault@sha256:04624614ad395cc936033b46cd210b5274a703c7a073056a695ce8545d2462ce
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/vault@sha256:66fd8ff84489c14d2133d884fab0e20c9841120b9c491a46fab6cdd526ec46b5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/vault@sha256:39a7ffcc35cc9bdbd93af652a6bb1ec5d7f8f5b615ac1254c91625b34557766b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/vault@sha256:bae729447b891f060f5d32718de066c0a4a7200c7aff161a36da02191b38b2c5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/vault@sha256:711d60353ac3bebf788d557733cce9e19f5fbe0d25bf0d106bc2e6291882c7fd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/vault@sha256:0094523854544c085dcb7a1667e566687bb261e42f8d3540508242ec98eed183