Sign inSign up
Harbor Portal

dhi.io/harbor-portal

Harbor Portal 2.15.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.15-debian-dev, 2.15-debian13-dev, 2.15-dev, 2.15.2-debian-dev, 2.15.2-debian13-dev, 2.15.2-dev

Index digest:

sha256:1ad501ba4386e39d6f1c8e4dd3a3c6b9e70b2a7c86a8f6b2fcec4d1d161d8a96

Manifest digest:

sha256:891956e9e51db7372b47161a9bea5ce5728b811ed2c5361aaa965e26b5aa9e2b

Size

25.86 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-portal:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-portal:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-portal@sha256:2c1c80c6d83940fdb240beaa29c2e4e0465b8af1a3727239aa787fcb9637bbdf
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-portal@sha256:a2c6b7c4e05ac56200cce791122637ffec18f4ffec3b18276986831c673bad1b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-portal@sha256:b6e6492db162188c800a10e97d39edb0816dcea494a64c0d8cc8e34dbd864872
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-portal@sha256:48b0487872b03e0061f44c3e1c8ef7c7b436f037d22b89ca10612a90c9df4bf2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-portal@sha256:f93c8030bd4bd472d1efb94cf481afe2a3d90116e919aee2da293c6dc4ea9cb0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-portal@sha256:b3fa93d9cfd82efb66cb852e570dee6131b67620202f6873ff7690ef92ce785f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-portal@sha256:109279d4b1af8fc7c71c427c0f0ba4e0ccec02f0009f2f82d559b67b2b819447
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-portal@sha256:bfbb379ab779068f7623a9fd7d894f1f0a2c8c2ee019993d346f2e2cab91d332
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-portal@sha256:e8c9de05b46d5d7bb55ff334ae1b24b376dc8261e9fe2ab383d24b6cac96e755
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-portal@sha256:4ceb88a327f32b280b4ab274918ac0730feb5ebc0558ceca7a623c07e3e173c6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-portal@sha256:7c1d0629281a7775064a0d0f056a8a9ff88f72cb25b4424058b273b6a59f3be4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-portal@sha256:1321ba1ea3a454ac0b43938c42f9e0d37526fcc9a016b5ee1d24975d548c0f56
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-portal@sha256:5dd0c9f8a6ae21df7bbcc0f394c33bcce66d9a330822fe97f8373749735ee8a2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-portal@sha256:9e9c3d8247324b8757b5b51fef10e6bf862e96e375b63df01d2c986ae79494b3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-portal@sha256:845dd2c8d3f64dbec5f3d86d085d85853c97ac779e4a534ff10d8afff7a4d598