Sign inSign up
Harbor Exporter

dhi.io/harbor-exporter

Harbor Exporter 2.15.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips, 2-debian13-fips, 2-fips, 2.15-debian-fips, 2.15-debian13-fips, 2.15-fips, 2.15.2-debian-fips, 2.15.2-debian13-fips, 2.15.2-fips

Index digest:

sha256:94dce50b280339e2802dcbbeed8fa2634c4b98dc331c7ad46845c743c3dfdf3d

Manifest digest:

sha256:b4863993bc737f4a69c9a354254606a7461f4721d657a40dde4b60145cb1e83d

Size

18.60 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-exporter:2-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-exporter:2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-exporter@sha256:7bfe40a5d11f3a207738b76c79728ebe4a8f1f281127745ec6f8519b64de6b07
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-exporter@sha256:5e96eb48bde9313b2a041e3f524e12cd0bc5e9c28d03f8deeb7aeab0db9091d9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-exporter@sha256:565c557aeb8698211568fdf6cde89911425ba67ed20dfdc32e11aa49275b5ad5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-exporter@sha256:3c01d9f8de625d4d0a80ab0a7dfb817ded86e67c33d6ffc5d0435f9b5b6a68d0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-exporter@sha256:4576d81f86f7513f36747650ae322a0e79de9ac0ccc54e11eb244bd8a03490ee
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-exporter@sha256:468341d125409cc95b8db5bed67169c4f136bbddd493b0b5aa951f8a0d7bbdc7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-exporter@sha256:8e05b6c60bea867dd0394db2305ea3a9f7424798743a3d32dda80a2b87d20b7e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-exporter@sha256:a1674f662852b9d164df2c7d443db6cb645e921d46cacd4a7fa85a2eedb341c8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-exporter@sha256:ee8dec3784c5648b90410480b93342d05a01f3d4905402322d63705d170ca208
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-exporter@sha256:53ba6307e1407f99eacd2fb43def94c457d0edb51e83e36048e9410b7fc85baa
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-exporter@sha256:f98e6d05267cb6b56c23abab990eea99b08a99243ebd199bb672267a2837c096
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-exporter@sha256:44a52dbef539af10bd25d6a4fee4103cb6248fe25ee07f1d934dcf08e1a6dd36
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-exporter@sha256:fc2fb6c84cc695e6ca0f72360b3da76b0923349ec8fc006ed43ce3fcb51d4946
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-exporter@sha256:6ecddac7a0b3bb38e54422d63572720979d6a85b9127ffe8d0e5c8d58a9347b8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-exporter@sha256:e9c6eb5e5adbf9d6dd6c51fd590f51da17da7453d4a841c69e4da80e796110f3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-exporter@sha256:be769988816ec816ed331e41e1dac0c98cbc175e8df01b121f816b65c8b2cdcf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-exporter@sha256:ca4ef76112199029d40d6cf204556256f6d7b202dd39051ff36338c613538340