dhi.io/harbor-db
2.13-debian-fips, 2.13-debian13-fips, 2.13-fips, 2.13.5-debian-fips, 2.13.5-debian13-fips, 2.13.5-fips
sha256:44873d8a58989a2cf0a4a73496618291d3843c3f85c3a9b250168773a0b81e81
Manifest digest:sha256:3a230c5e3fd0ef0cd519383fa2d7438673b48c9ce00bf12b312ff9371277e073
Size
64.69 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/harbor-db:2.13-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/harbor-db:2.13-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/harbor-db@sha256:80c15baf140d3fa97e4a2da5d75a191b54bac98df097d4ee701b463e0f97a016 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/harbor-db@sha256:9bc6aad804285997e423fa6f0193960009379272c3173b8aa382838b79e6e95a |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/harbor-db@sha256:c20eb64d4c911985094d66c44912464c75c15c2f9bf2dd0e1b3e40c26357dcd1 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/harbor-db@sha256:b64b6add747a924f13bcba0673e68afe7546177f4c10d1859cfd35901429d6ae |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/harbor-db@sha256:2671735d1198fd760af65f5d913481e2fd0577e34f72dc9b5b41acfd786fb2ef |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/harbor-db@sha256:b7d592f262d9329a6823922a201e52d9b91a7a6c82535335c3ca9fddf4abc717 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/harbor-db@sha256:ec190e9ea17ab35ae6fe8808fd94fa91fb7ed626994aae38c74b12b95ec714b6 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/harbor-db@sha256:9a50cb6f4ca5c3c6a4b193dccd0faf8cfbf4acce7def48894c97775b4adf1875 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/harbor-db@sha256:bdbfb8573871fa1e9a7e1ea13537d7a396cc9e7f41889dddc2fe1940ca27d8cc |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/harbor-db@sha256:d2eaecf8937749b5298a4f172d1a9bb2d416ea41357a5eeed64f1ab34a8a2030 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/harbor-db@sha256:028524f4bc9c384bac93c3a4f5b2fa3f1f2c2daf256998ab451dc132bcc25207 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/harbor-db@sha256:ca60447c0c4938edf13d4975e0177b3eb4da0d5013d01532793aec795d4837d1 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/harbor-db@sha256:a75b65064124824cf11fe9caec78d85c433e708445755ae66dfc47811469c8a1 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/harbor-db@sha256:b16d7cef46242ef9e2bff2ecc4e5522d4e2dd1351e6b9de1bce1ae201632e259 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/harbor-db@sha256:c743959165f04d3c180e94b4e73bc15156d92a8bd337a669f2e1e64a36902a19 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/harbor-db@sha256:377337b4b0d7bab49913e90d84b7fd5bc8d37f4a768e1d3074ef081d7fefe16e |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/harbor-db@sha256:4d969510acb9ae000fa8327016353057868b90cfac252690661b39f775fa7aed |