dhi.io/harbor-exporter
2.13-debian-fips, 2.13-debian13-fips, 2.13-fips, 2.13.5-debian-fips, 2.13.5-debian13-fips, 2.13.5-fips
sha256:a0c333f9d624f2a2496d7133e1398d320aa48e12c524b30ff279cdbbd8d97d30
Manifest digest:sha256:97a7d5510df37b6231632535acd9b7b193b2eea14d812416386727876f9c1e63
Size
17.59 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/harbor-exporter:2.13-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/harbor-exporter:2.13-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/harbor-exporter@sha256:1e17335e5b8814acfa4f5bdd6f5d101ef294e41e36f9c72bb18cd081eaff675d |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/harbor-exporter@sha256:782c6ed5de018a7e71d1cb1866fc43fdd817358729e7e96ab138ddfdf2285578 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/harbor-exporter@sha256:e404b13cd3accb89d8761d419b329243d93afe15e93703cb952d63dfe937e789 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/harbor-exporter@sha256:79ba30a68dd75c95d8f3fefa94d7cb1f47ae1650a9867a07462f8bae73d22af7 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/harbor-exporter@sha256:8f5cb0e787fb6837be25acd9beba4b5df5ef2c91a25fb7e64b4247b574ebbc5d |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/harbor-exporter@sha256:5d7ff975eec9f96e6e5146286327f9cb4113cef7b8a184f4cee1ab550fb21602 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/harbor-exporter@sha256:22406e24c3f5dd16006508254d5e74786b08873eb381cd607f6b800c4ec0a4f8 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/harbor-exporter@sha256:cb9cc0d85230ec351799cf15d3ad3672271ac1cf852469e15d2e931eca9d4154 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/harbor-exporter@sha256:52c1540584d5b3839c323883a3a8a82945846a4a0651d606ee74adda21f79d20 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/harbor-exporter@sha256:09eae2650c2788570a9f18cde1e068ec8148586bb2cf7761a105e04e9dffa82a |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/harbor-exporter@sha256:b87701f9b01b4dfdf69f5b5770d2f523209cd96ed4999bd25984720a0dca4037 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/harbor-exporter@sha256:03c98f80c1ca1a1b95f3c3c320585a43a9ec577096199359ff89b54b96d3d149 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/harbor-exporter@sha256:c182e1a9036241443581aa1829272e757cc4d3e82a989ca6d80ebf586c8329e3 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/harbor-exporter@sha256:3554e7f6776cfc28535851b621d29fa6f90c11080023657dd5d4d1aca0b8f9c0 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/harbor-exporter@sha256:6825f630cb12935f6ec19aed44507a354cc76ed077cd1d747f8c90a3c2b65480 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/harbor-exporter@sha256:7cb6fed46acf72d750f2b8c6fe29f1dc1b85119324fb4848e159f43a91d889c0 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/harbor-exporter@sha256:0b5a7f3d027847ff072c5a2f75bf06562d15d9e34ad463380bf7564607f8307f |