Sign inSign up
Harbor Exporter

dhi.io/harbor-exporter

Harbor Exporter 2.14.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.14-debian-fips-dev, 2.14-debian13-fips-dev, 2.14-fips-dev, 2.14.4-debian-fips-dev, 2.14.4-debian13-fips-dev, 2.14.4-fips-dev

Index digest:

sha256:c4b08f2ee84bf4873bf49b02cdbf4bf79fd65cbcb483b0ccffc75f5d5f666db7

Manifest digest:

sha256:9d4c314276c037a099332cb652de2f892002a000fd22ad9790876ed0f012d483

Size

41.14 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-exporter:2.14-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-exporter:2.14-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-exporter@sha256:8f975eaf6feb108338d55c8791d286dc185d58206918e654ca8583295f27935b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-exporter@sha256:50c4c2efe68038c6f80b30df91b6e8c8e85c9947265754dc01351dcb06d627d2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-exporter@sha256:c30e6d6c73920b0d99f388390f63c8b7a01003a32329e33a13b4973655fb0172
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-exporter@sha256:7f8efa9a5f513b1dede447c97b5fb28f9bfb74b2c0eeb87237231007dbce487f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-exporter@sha256:386295f52823d051199559ef0a1a34248b17c74568cbaa7c9d135d7f58894265
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-exporter@sha256:b07c73e52be180e94184225d4454d08a367d72f9cf30919bf25a705377b7ce76
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-exporter@sha256:e37afd469fcc54a1c316a6664a7f4dc5f5fbc026fbc60fdbb45042994a095a7b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-exporter@sha256:3827468ff638f899b26186a3c9c793c8c0d10b205c2e8cde016b30930ab42d79
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-exporter@sha256:8e585b5de9412f113299939c9430e7f58c1cc1dcff74e1b23fac03c9d32ce9d3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-exporter@sha256:56aa2e80867c66d38a345d314946d3d704157dfe58f52d6089ae6289f30f864f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-exporter@sha256:a5bed4813e60ac4d034bcca4107ac7f839a0a26a0a254b24741d9353c6d99d67
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-exporter@sha256:199cbec6027283f9fd3b79adf9685068a537092a99b86bdcc78b1a6e0b70d68c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-exporter@sha256:72352fa191ea67905a3579f80a57a0205c394cd8d9a0f478a50eb4d49acba2f9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-exporter@sha256:100d28281f8bad69425450fc0055856211b5fb85dc6671919d9f838ca5904d4b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-exporter@sha256:92c911fbc3a7740ac64927e7ddcf73f27b829ce9f78cb425e0c73d543589aaa1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-exporter@sha256:16353bc1daee1706a71d1a9d827f9db16325bbe5a93996bb51c3a77243a42c21
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-exporter@sha256:bb595ceb32427d45161c2f207bcd2d42d8d141e8f82b82926bc7123f6e8fca47