Sign inSign up
Harbor Portal

dhi.io/harbor-portal

Harbor Portal 2.13.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.13-debian-dev, 2.13-debian13-dev, 2.13-dev, 2.13.5-debian-dev, 2.13.5-debian13-dev, 2.13.5-dev

Index digest:

sha256:cae7bbbbda1cd0ff1255d7a32e93f9d8925199770e2e771971f128761c7fdc1d

Manifest digest:

sha256:5f9852deadc86c07ca17dec6244a1ec1bf25d8aaac05a7d6e17569b1432f7a10

Size

25.60 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-portal:2.13-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-portal:2.13-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-portal@sha256:b684dad1a6eb5a4d8e87dcba3c220d3820b2fa9edd3dd91ece3c5c1e8c79634d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-portal@sha256:31e5f2a711b41d049413aed7813e8478e32fd7daf7d2cb3ba0a86bbcaa6cb327
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-portal@sha256:777f6b0fce3de19ccae7f8ebcd3efcdf2f359aeb18b5777478dd1586cbc37441
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-portal@sha256:2be0fcf6fc3d736c84a4e5f82e134b74e01edbf0a97b9215a5ee1cedfc339ce3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-portal@sha256:3cc1b88a1a33bf77eb2cd04865593b59698d48e29e102b399d88fd8c8ae7ebfc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-portal@sha256:0e471b130ea9a4f88155cbc18ba50e5e5754c97e19a84d7297832ed1290d8dc5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-portal@sha256:81d9e653761ed89fa221c7f80ab4ff84ea33205a081b14f7c449b8b307221128
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-portal@sha256:2acebaa7e62a894805e37c3c762765236d650a4dbb28847ace45e6380692978a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-portal@sha256:cc50199a15674cb01effae5acc3fba9fab83fa175c26bd9324e857fef0cb9fee
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-portal@sha256:04a65f97177a76b3f6a5e1b8bb97630924b8a3f9ab105d0e5ea87da184fc6f21
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-portal@sha256:d0c9d0dcd7b26f754c2a6df84eecf5a3c5a93b999959cf135be0c7e00a3b2807
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-portal@sha256:f1befd81add256a467dd2ed7436dbd6ef6563736c57a577f7c537a0fc3c8e99e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-portal@sha256:c777f8f5313fb15b9893262689ec04eb8e1e7dfc359e42a65c34fe49218b2bad
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-portal@sha256:32e5d7e2e547889e3256d274260084f28f081f2e43fd019e119aadcf979c3509
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-portal@sha256:cb43838c6c03f18d28f6d163f117b9647fddd2759814727bb5bf992e8c5ab965