Sign inSign up
Harbor Portal

dhi.io/harbor-portal

Harbor Portal 2.12.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.12-debian-fips-dev, 2.12-debian13-fips-dev, 2.12-fips-dev, 2.12.4-debian-fips-dev, 2.12.4-debian13-fips-dev, 2.12.4-fips-dev

Index digest:

sha256:ce682e3a891078bd87cf5c9c222a86ce8c0670b451d76eb5f3cabe19b9c34523

Manifest digest:

sha256:f39c9f17dc94f9d785f8dea816f75c11fbc23b67a382b2e6dbc6d89acfbee00d

Size

26.34 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-portal:2.12-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-portal:2.12-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-portal@sha256:5799c274f3c7b43f683b2b06d5b03cdf998718348b844a30e7a9b68525f0ea6a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-portal@sha256:4ff3ba70a093408a025d7ce0f66095a32bc1186e02cf8da5beb321daca2b6a84
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-portal@sha256:0f1ed5b0c5dc4a0948ed53a9de7d13cd2e9dd9c51f59ba972f3cc2aaa5ba4c4d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-portal@sha256:b96b0b987d52756e468bd31fc6195a0251ecd3a2cc16a43a6ac79c0668d99d0a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-portal@sha256:09c5ab3877c00e75b53653608183e569d84b8ffae82b3952f2bde3a3eae57136
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-portal@sha256:edae9bc1ebe8b8fd853ee27cf901db2887aeab48e181c1a0e5263287c37e234c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-portal@sha256:06cf4dc0860e3ca280253b401d3b93909c7c074ee3d225fc04f92c5ad4c91689
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-portal@sha256:7472353ea0abd1a95f7e7339f774c7a1ee3e6948fa21b89557da1a36fc7fdfc1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-portal@sha256:0c9a1707d4d09553734d4c4eb5c8097898f1f273ac957ebb961cda073742a2b6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-portal@sha256:711ea8a2983b1c2617f74f283da656d32301108e5a82a945862b6497d28a59be
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-portal@sha256:d49906d20062534200899019e9d9a86f2d5ff95b26682a4b4620697f6c089353
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-portal@sha256:82d3ea07c9d598adb0c25ab85213a3ff1059365c624f9e13aeeb9bbe78ba8392
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-portal@sha256:59971d78de2904eebefc909f27b3f20a83b2e8e035f949fc21b19d729286dba2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-portal@sha256:e70a81b6414e4447e38abe32dc32ba3505fcbe9bdc8e2a881cc7e5323840b23d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-portal@sha256:61dbe43c58032d74cb55dbf6974b863599178d15578d14bd5f449a447f56422b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-portal@sha256:e78aa38f956c4f0c2b8aeed698aec3034050abd5d93fc441c977ebfb0b1b75aa
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-portal@sha256:05d8b91ab28b35f6a6f767bfeb448a4fb82143af049b56f28d08fbb968154b5a