dhi.io/vault
2-debian-helm, 2-debian13-helm, 2-helm, 2.1-debian-helm, 2.1-debian13-helm, 2.1-helm, 2.1.0-debian-helm, 2.1.0-debian13-helm, 2.1.0-helm
sha256:84cd90f2ba372cf5ec6892ccb6d87aa3bb57a0f1d16a3ac00b09ca164a90549f
Manifest digest:sha256:a0d23b229e0f242efee6118ee1f6b462aca39534ad6ca4b75b94f607f742e0ae
Size
89.57 MB
Last pushed
5 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/vault:2-debian-helm2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/vault:2-debian-helm --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/vault@sha256:446d7df470c7b41bb06af05359301d6f6e208ec45d051efe48d39af9b294dc7d |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/vault@sha256:6acbec8db27e2bcae5c02e8d5bd2c397c654b703852a2d497e7a6afc6a2e129c |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/vault@sha256:375b25ce626ba4c955709977edfe85fa7f0e5a3edd96d1d2503471ce89850735 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/vault@sha256:678e6c6e570302e39188188261e373c89516395d5f5b67a1cb81226f948ef071 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/vault@sha256:9f9ac69c24074db85b585e3746044bd48629182d26fdc11c291125c5d0775bbf |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/vault@sha256:1d69df4391d13433074bbb551777a1870057b39108c59e5d6c3e0221414af23a |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/vault@sha256:b60b8b59c0e9dd290b038fcafa38a33890b76e5bc03d3c34e5f3e07a0850d233 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/vault@sha256:ab7ecc6ca108a5f4bab88ab87603f13a7cdaaa350140d8c9113b9b2e8599dc26 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/vault@sha256:9f7b4ede4d3e9871a16aa6eca042a8d946c445b36bbc2648d3dfc517e27a9431 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/vault@sha256:3920c98b955f92881583112b2172e8e567262950323bc077a53eb0c552a0f943 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/vault@sha256:0d7d80b24fcebdd4a61173c2e8a302499f81ed71bbe5df6fc04d642ff17f57ca |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/vault@sha256:21b221924a0a3d0a9555adde76f0118bdd29b10c190e716a4b17c8c0ee37e9eb |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/vault@sha256:6a0f5664f838cfbb123e8c7ed15db938337285ceb5eba94934d20f0f73dd5c5e |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/vault@sha256:74d5aedd40994cebffcc55d1cd7894fa9e09c284cef0b54800ab3f621c6c08e8 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/vault@sha256:bf1a96e4c10fe2967e818894a513ec17a99f8d33d11d91745d03992fd07bdc4b |