Sign inSign up
Harbor DB

dhi.io/harbor-db

Harbor DB 2.13.x

CIS
linux/amd64
debian 13
Tags:

2.13, 2.13-debian, 2.13-debian13, 2.13.5, 2.13.5-debian, 2.13.5-debian13

Index digest:

sha256:d342f9a73d879f51f735a5a0b37bd06d5a42fe66c6f102e594cb6a8e6c69fed1

Manifest digest:

sha256:105ffe8c9619b1e5d617e21411eae553025cbab78774d77d3863084c7056ca3b

Size

62.43 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-db:2.13

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-db:2.13 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-db@sha256:c5bd4cfbe767e5a3f80fd6af1c468e8dbf6b869fecd26c4c965391e978eb40f2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-db@sha256:0d14f4a50f5cb9ce3bd8e5f9de685985bc41213609f0b0a9621a0e74a0a7a456
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-db@sha256:73ee42f537e5d01926d84e3495d9cb48e5a03381acb9357ee9b7fc4ebe38d7cc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-db@sha256:ca70ca22fcac9ea9bfbd8280bb0b752a7a488053dfb0df9121a49e9b3d017b70
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-db@sha256:83fae2b58be17fb745291aa45cad0ef14522cfb818a968da8db8a7fc805a32ae
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-db@sha256:50c0712b3b999b97d19b10517070edb0028e25a0e887bb0d7abe08968af5d453
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-db@sha256:98ce6e0b737a89bd6c0526a4f32d89d88f8f1b626baa2dc4d6faf88754b43d36
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-db@sha256:b99a34555b789d1d7e2563fe0a0560eda2b41e18d07df51f0a047ce4ee11e39f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-db@sha256:377e978e4e2845edbc4d11c78a8141d84cc4322eafa76f3bd4aca3ee07b87150
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-db@sha256:b1afa1277a19bd46a686b4ec8c9bcb7334bbfea63e73ced7abd734da62759ad6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-db@sha256:04742b84cd8ee3bfc5c011a41051ac010366d60607a6d13d6b242e0d485ca00c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-db@sha256:f60f09cd79b2a3f001f87b97758d11f43a1af65e816e9135ad70d79975b3cfa6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-db@sha256:3073bd784a89e5ac51b2dfc8b9e7233de8890b45e6c60764634e1bcc728fe887
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-db@sha256:f63bdf71dbfbc44dd0dbd4d7ba62cc0352055e822dd47f7ab47bfcf05c255feb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-db@sha256:70c9443a9ac484e009adc0794c5b65b627aacbd4f4a80b47495a28debdc5b300