Sign inSign up
Harbor Exporter

dhi.io/harbor-exporter

Harbor Exporter 2.15.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.15-debian-fips-dev, 2.15-debian13-fips-dev, 2.15-fips-dev, 2.15.2-debian-fips-dev, 2.15.2-debian13-fips-dev, 2.15.2-fips-dev

Index digest:

sha256:e1cfb96d28c3f4689dc4ca9c1f81307be63ce263bae1ab161117194275a42ad3

Manifest digest:

sha256:68b308cb464673e612028d8008ae20d7e9ba74a9f37f32a263ee5333857d14d2

Size

43.17 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-exporter:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-exporter:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-exporter@sha256:5facf5d5808de3006a0bac2b6a1725c744ac1b5fc34de2954e7c59f9d81888ac
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-exporter@sha256:2afa49de018e9b91eeba171635bcaaf9b4d0e1f3fa3cede9460b9f966701b786
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-exporter@sha256:df20296a1af1c76d9e177b7290b4c638d1a5ba97b5207e3a2861e30126fbcf98
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-exporter@sha256:e76dd833a28317a491f545f56c145f0abbcb29346d772176d0f940a482a751e2
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-exporter@sha256:2ce46a76d6333c765671add0a993a5ba4405d9232a54471fa92274e984b37819
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-exporter@sha256:795d8062c0465190836aea5fabc545aa138a7d0b587098eb886d2bec233b00f2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-exporter@sha256:07150bbebd014549a46858ebc277b780218820ee3b8cf5543b07b4c641123c27
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-exporter@sha256:aeffa60d83e88dc6fbf0f2f908c91453fd726cae559e469cfd8be9874f421c10
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-exporter@sha256:b6eff1336565a8a617e4a467cbad255c95ae81a1d07241e48a0d929d01550e3f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-exporter@sha256:2f27bfd775bb19c05c36d99631d6d3badf9e58fae5b9a54cbcd01da047b22ac6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-exporter@sha256:3f62d0ba96c715265b95707b2dcbe888e85c52fbc89fd8028b22cd7f45b0d29f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-exporter@sha256:b32b3df2a19b52146674f78459a7e545b5fe36bea6b4a72b25254c267c6c0cbb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-exporter@sha256:fc17551cecaa65e55567cf9e8a2db666ec282fc534b3d29fbef1084e37815578
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-exporter@sha256:bf872a35e9b814d5e01cfe12bd804601964a44ccba72a5ad25e5ad67ae9f7d47
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-exporter@sha256:7f68af8130ce215616ad01833e1442939981a431b9263b638df0fb00a6343974
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-exporter@sha256:c0d0d592ae48e3fd1758b8576351c1af2bc1eaa7d45013eeb8be827d406fd157
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-exporter@sha256:a5a8175134d8d9215e94b71e6f46c69b81ae68e5fdcbd747fc61726c99b67b60