Sign inSign up
Harbor DB

dhi.io/harbor-db

Harbor DB 2.13.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.13-debian-fips, 2.13-debian13-fips, 2.13-fips, 2.13.5-debian-fips, 2.13.5-debian13-fips, 2.13.5-fips

Index digest:

sha256:44873d8a58989a2cf0a4a73496618291d3843c3f85c3a9b250168773a0b81e81

Manifest digest:

sha256:3a230c5e3fd0ef0cd519383fa2d7438673b48c9ce00bf12b312ff9371277e073

Size

64.69 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-db:2.13-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-db:2.13-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-db@sha256:80c15baf140d3fa97e4a2da5d75a191b54bac98df097d4ee701b463e0f97a016
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-db@sha256:9bc6aad804285997e423fa6f0193960009379272c3173b8aa382838b79e6e95a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-db@sha256:c20eb64d4c911985094d66c44912464c75c15c2f9bf2dd0e1b3e40c26357dcd1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-db@sha256:b64b6add747a924f13bcba0673e68afe7546177f4c10d1859cfd35901429d6ae
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-db@sha256:2671735d1198fd760af65f5d913481e2fd0577e34f72dc9b5b41acfd786fb2ef
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-db@sha256:b7d592f262d9329a6823922a201e52d9b91a7a6c82535335c3ca9fddf4abc717
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-db@sha256:ec190e9ea17ab35ae6fe8808fd94fa91fb7ed626994aae38c74b12b95ec714b6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-db@sha256:9a50cb6f4ca5c3c6a4b193dccd0faf8cfbf4acce7def48894c97775b4adf1875
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-db@sha256:bdbfb8573871fa1e9a7e1ea13537d7a396cc9e7f41889dddc2fe1940ca27d8cc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-db@sha256:d2eaecf8937749b5298a4f172d1a9bb2d416ea41357a5eeed64f1ab34a8a2030
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-db@sha256:028524f4bc9c384bac93c3a4f5b2fa3f1f2c2daf256998ab451dc132bcc25207
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-db@sha256:ca60447c0c4938edf13d4975e0177b3eb4da0d5013d01532793aec795d4837d1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-db@sha256:a75b65064124824cf11fe9caec78d85c433e708445755ae66dfc47811469c8a1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-db@sha256:b16d7cef46242ef9e2bff2ecc4e5522d4e2dd1351e6b9de1bce1ae201632e259
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-db@sha256:c743959165f04d3c180e94b4e73bc15156d92a8bd337a669f2e1e64a36902a19
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-db@sha256:377337b4b0d7bab49913e90d84b7fd5bc8d37f4a768e1d3074ef081d7fefe16e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-db@sha256:4d969510acb9ae000fa8327016353057868b90cfac252690661b39f775fa7aed