dhi.io/harbor-db
2.13-debian-fips-dev, 2.13-debian13-fips-dev, 2.13-fips-dev, 2.13.5-debian-fips-dev, 2.13.5-debian13-fips-dev, 2.13.5-fips-dev
sha256:a2716b39e142527cb67b242de2e8f2ef70014729ad997f7f37a29fd59887c52e
Manifest digest:sha256:45a239ae68f052351333853d9f56b9247731f030095459b0d5bd0e8ea2bca0ae
Size
74.77 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/harbor-db:2.13-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/harbor-db:2.13-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/harbor-db@sha256:52489a46c50d69d9cb5a284b8fd17dae964d483bcd4a687563371d68f05e8b53 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/harbor-db@sha256:7172968aaf116411692173ae373299646047069f22b2bf0bcd91a9024eb61ce8 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/harbor-db@sha256:ee6e15811d3c1f95275604338eeb6a7002957445360000cfac3d8951853cf8f6 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/harbor-db@sha256:7ff6015c0e64ded09429a936440f82d865e8ec9735e72037d208af72745f058b |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/harbor-db@sha256:bf0579ee92e96132b469c0a72c76a05e5f5c8cc249fdffd83ffefffc9cccf75d |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/harbor-db@sha256:bfff7c8d23061583de91b3678fb56d4d5112f3fe894f0863a821e49e87a9a94b |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/harbor-db@sha256:70c167aefd1d72895de6bf52a23632cc32bc9a0cdd5de0ddae7f24f8d51ed3d7 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/harbor-db@sha256:05cbfd38f65040f6e7b9333af6642dee175b973aa177d88b70159a549ba5bc46 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/harbor-db@sha256:ecbe292fb836e02366d95d0baf314ebe3fc2ac00b217516585963be18cb92cb1 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/harbor-db@sha256:067a7af04230ed1aea0d0afc91834945e59f5fe3a6d0525541de1bd8aee18eb7 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/harbor-db@sha256:8766afbacb670f95538d6b332a25d87e9e2c59b30eba7f357659a0880ba9df6c |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/harbor-db@sha256:5b9bb736e9cc5639d16eacf90291ee364e6bcb5a57d4e269ce9ab77907637950 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/harbor-db@sha256:e39bdc6773c19d45237b6aa5caad3fb1aaa1362c30b872768830ddfa07d6fa21 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/harbor-db@sha256:d1a062c13432e453f9f696c7ef12f78f21682531721fbdef9f3dae438f8ee6d3 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/harbor-db@sha256:0625f001df5ab01ac6170a4aa8adfe75ab34ed4226bcbdac73462963c7a8c3ab |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/harbor-db@sha256:c0fec1f617c2e5229418022dd9a5c24ecab451715001d93d26aa0438b1088d8d |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/harbor-db@sha256:ea456aec7ac32c0515ffcf4891eedaedcb5c93263fb635d3f36869dea37a7c2c |