Sign inSign up
Harbor Exporter

dhi.io/harbor-exporter

Harbor Exporter 2.15.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.15-debian-fips-dev, 2.15-debian13-fips-dev, 2.15-fips-dev, 2.15.2-debian-fips-dev, 2.15.2-debian13-fips-dev, 2.15.2-fips-dev

Index digest:

sha256:7e89355969316476a7247caddf1c37d11dff67025e611a938023a924f142a1fd

Manifest digest:

sha256:9fcc16d4e378878face2af3865c192fe1eac7c6b5c150a162969d835c2f119b9

Size

43.17 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-exporter:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-exporter:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-exporter@sha256:36242620bf420c582cdba4c0f5699630868884bc33b57b78803f115fddffe3b4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-exporter@sha256:08ecf777b6470e827b19021623c3a1cfec3041d9ec1bacad85dd8ac01a4477f0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-exporter@sha256:ba02268955f544bf4ab538d05333449c645a5c8e5f55295373685c80b573a695
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-exporter@sha256:ddd4354fdf2cda1520e981b85628dc8632f2f8c1ff65e5c6e7d0ef827a564de8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-exporter@sha256:74f6e29d993f11c9f7073bfef6acf2a65c16a3c76d47dd7dfcb6c1310418dfb6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-exporter@sha256:2b419e20b46c3e8e5fe0690b1895c69f3a93829b9fee8ecd5e8750494b9cd47d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-exporter@sha256:0d60bbb015f5c12b507badc823861e817a9ca4563a44f1972c679ca6a21fa17c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-exporter@sha256:b22f4e7cca681214af2767374411fa215490531c105ebcf71ad4e949c3ca1271
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-exporter@sha256:f8694ae3f0cf87c1e98a20e2d7cd475461adaf6d081b785d23b382ea4f1f3aa4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-exporter@sha256:c643f355b0430aa0ae651fe33e4de7c330948542439dc880494bf41b72086705
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-exporter@sha256:e1b4bd243ca6625aa9d64ac592bebfcd238704d06ea55af5fd6b642af39dfdeb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-exporter@sha256:f3501ababfe1b4636290de76b28dd259d453ccd9dfcfaf7d76692ed1c2a1a71d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-exporter@sha256:ce022c9025ae26c54025cdaa92933dae7ba111aa3da5fbd149c6cfdf1fc5bd6a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-exporter@sha256:a4441031ed4ce81a5dffc645e4aa7bf154fc0d3a7fd9ada4e2cc0aa2942314a1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-exporter@sha256:5e52b50d520af1369ce1c11f8da303dc2c053f710bccbdd0f246ec9e4b23237b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-exporter@sha256:2440aa97512ef481cb7fd66b73e0ebf12fb337c3a232a0d1392788b8d727aeca
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-exporter@sha256:6177a909fa5061704c8b1a7b141f0cc1b9956060485864744bfbe4ed30bd817b