dhi.io/harbor-portal
2.12-debian-fips-dev, 2.12-debian13-fips-dev, 2.12-fips-dev, 2.12.4-debian-fips-dev, 2.12.4-debian13-fips-dev, 2.12.4-fips-dev
sha256:8b5c96f7ead868d909212124c2c66ba9ca9519c928fdb51832c7ba7205aca4b7
Manifest digest:sha256:0ebe21c05df9390a23667f0cd7ecb3a48e58019044d794e028c51b93a01ada54
Size
26.34 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/harbor-portal:2.12-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/harbor-portal:2.12-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/harbor-portal@sha256:2d06b291c52f27ab3c54e9ea3a1cb8f85b51cea65e3e3b7749a1d50673d85df0 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/harbor-portal@sha256:3d5ab7fbb8b29e7f33c4e85cb1a27877517fc60787c5ee0a19bb097a0f283bb2 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/harbor-portal@sha256:8cfd5cb3f0d0112d03f8ce9013db69213638b18e71c60f03643fb953e717c0f0 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/harbor-portal@sha256:a11a42624ea690f2b63bf52849f10c04aa6b4383e7d83780eed2928acb078f0c |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/harbor-portal@sha256:6d3361d234b548543e6c38a7e0ea884abc9544cba4de367b4722a8c1e87cc8c1 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/harbor-portal@sha256:7d1655ae818be431aad5dec5db0bbe692047cda10e2d0696b6f6f35a01594d8b |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/harbor-portal@sha256:267bf255b9119ad3393e7a721639c6da3c85ecc2c7fe24c1d3c7adf92b47580e |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/harbor-portal@sha256:a00ae2d2918ea5068872b4fdd33d2ce8c80740bc933c128e9be708b273f3a3d0 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/harbor-portal@sha256:50ca73630cd97d4c1432b3d4a292ddcbb67ad6900fb2f27adb0e24c4c303dc28 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/harbor-portal@sha256:5a8efdf72615fb429aac097008e168470293b9aa952fd3269bfd7238cf3e37e8 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/harbor-portal@sha256:3efd45ceec9d809daa0c8b594cfcb78c23baf319dfb634f1a5c61f6ba673721b |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/harbor-portal@sha256:e35e17ade63d6a1848d0da20a4586f7ca7064588c52b62e12f5985185aef2fd6 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/harbor-portal@sha256:f93b109f95b02d65ce565b2c14fa23da1c7b34701706c16eb8496d3b5bfa0759 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/harbor-portal@sha256:72830f90e42ad1bbacff2a9791e95fe658ca44eca446c2802dd8e6ecbb51f65d |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/harbor-portal@sha256:9e15cf822c6c0bc17eba200241b4522a38ff686c2d5a1372f38b0ceddad53137 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/harbor-portal@sha256:115c178689d6f441393ce1b3783ec9b832021b52a80f5ea5ec89ca445fa175a1 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/harbor-portal@sha256:74a07be216717a15e930e1517c2256321c5c4adcacc84963534b142c09c701f6 |