Sign inSign up
Harbor Portal

dhi.io/harbor-portal

Harbor Portal 2.12.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.12-debian-fips-dev, 2.12-debian13-fips-dev, 2.12-fips-dev, 2.12.4-debian-fips-dev, 2.12.4-debian13-fips-dev, 2.12.4-fips-dev

Index digest:

sha256:8b5c96f7ead868d909212124c2c66ba9ca9519c928fdb51832c7ba7205aca4b7

Manifest digest:

sha256:0ebe21c05df9390a23667f0cd7ecb3a48e58019044d794e028c51b93a01ada54

Size

26.34 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-portal:2.12-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-portal:2.12-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-portal@sha256:2d06b291c52f27ab3c54e9ea3a1cb8f85b51cea65e3e3b7749a1d50673d85df0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-portal@sha256:3d5ab7fbb8b29e7f33c4e85cb1a27877517fc60787c5ee0a19bb097a0f283bb2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-portal@sha256:8cfd5cb3f0d0112d03f8ce9013db69213638b18e71c60f03643fb953e717c0f0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-portal@sha256:a11a42624ea690f2b63bf52849f10c04aa6b4383e7d83780eed2928acb078f0c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-portal@sha256:6d3361d234b548543e6c38a7e0ea884abc9544cba4de367b4722a8c1e87cc8c1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-portal@sha256:7d1655ae818be431aad5dec5db0bbe692047cda10e2d0696b6f6f35a01594d8b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-portal@sha256:267bf255b9119ad3393e7a721639c6da3c85ecc2c7fe24c1d3c7adf92b47580e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-portal@sha256:a00ae2d2918ea5068872b4fdd33d2ce8c80740bc933c128e9be708b273f3a3d0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-portal@sha256:50ca73630cd97d4c1432b3d4a292ddcbb67ad6900fb2f27adb0e24c4c303dc28
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-portal@sha256:5a8efdf72615fb429aac097008e168470293b9aa952fd3269bfd7238cf3e37e8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-portal@sha256:3efd45ceec9d809daa0c8b594cfcb78c23baf319dfb634f1a5c61f6ba673721b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-portal@sha256:e35e17ade63d6a1848d0da20a4586f7ca7064588c52b62e12f5985185aef2fd6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-portal@sha256:f93b109f95b02d65ce565b2c14fa23da1c7b34701706c16eb8496d3b5bfa0759
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-portal@sha256:72830f90e42ad1bbacff2a9791e95fe658ca44eca446c2802dd8e6ecbb51f65d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-portal@sha256:9e15cf822c6c0bc17eba200241b4522a38ff686c2d5a1372f38b0ceddad53137
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-portal@sha256:115c178689d6f441393ce1b3783ec9b832021b52a80f5ea5ec89ca445fa175a1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-portal@sha256:74a07be216717a15e930e1517c2256321c5c4adcacc84963534b142c09c701f6