Sign inSign up
Vault K8s

dhi.io/vault-k8s

vault-k8s 1.6.x

CIS
linux/amd64
debian 13
Tags:

1.6, 1.6-debian, 1.6-debian13, 1.6.2, 1.6.2-debian, 1.6.2-debian13

Index digest:

sha256:df3d16b28e2392e8e4abfc7182d46833a636098a00797c48761722a616ddb8e0

Manifest digest:

sha256:6bc72b258cb37cf94d49a9b181c924f3bf4a98cf549e245da2e581eb0b1f4db4

Size

12.81 MB

Last pushed

14 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/vault-k8s:1.6

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/vault-k8s:1.6 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/vault-k8s@sha256:fcd09df4199fefcb8f357fae4e98eacacfa98bebfa3efc393daf56df7bf919ea
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/vault-k8s@sha256:a58f3ecfc870a0508a3fb0b8d1e630c8288d04c8b19e18826ff885dbd9cb5901
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/vault-k8s@sha256:5494be7061b8968a608c12356d133b309c820de4c3fc95fb606e039a1383bf58
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/vault-k8s@sha256:6bde0280b5fdd5a2c5440deb3d0ef70835adef165c1848ab5904ea2ad424b7a9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/vault-k8s@sha256:5435d8a0e740b3825240a6d9f13bd97b51c5a3416ab512ec09c6375a9f33fc10
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/vault-k8s@sha256:ff47075c8f33e97aebd6638cdf7064b219c7ccd17f1a7786799d955ff25fae5c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/vault-k8s@sha256:1fe448c41f8fd0b23643b23d44c6ff7a9d602443626204d17eb5f1f67e828be3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/vault-k8s@sha256:c1ec99efee089bf115efbe4e45f590a673cab186b5d1011dbe089f6388692a49
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/vault-k8s@sha256:8da2abb7f8aa6e26b09812715f42389aa96d802952175ea46418d9abc7b1fa2b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/vault-k8s@sha256:6bde81f914c2530cc761f641d50d581f5a5f136200cc4c15c7f5b96e2f98212b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/vault-k8s@sha256:4c60feb1766cfa85316a766015c978677791fcd3dd22baa0cceaf98c798023e3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/vault-k8s@sha256:263a26e63bb87b157c717607cd2464dd4aad16455f627dbd9eee53c1804311d7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/vault-k8s@sha256:0b49458eae93ea3b110aaef46d0c7e061e4cec436c13a84efc857aa30133c664
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/vault-k8s@sha256:ecbe76595df1a6c3ec644f3d9a3d93c860d3eff0b4933af23a081566c1afd531
SPDX SBOMhttps://spdx.dev/Documentdhi.io/vault-k8s@sha256:40130e48be95300c3a936e4d24a94ddd0a75bce91fc8e7475a7971fd3431e1e4