Sign inSign up
Harbor Portal

dhi.io/harbor-portal

Harbor Portal 2.15.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.15, 2.15-debian, 2.15-debian13, 2.15.2, 2.15.2-debian, 2.15.2-debian13

Index digest:

sha256:ed4b38917861f2009e8d73ad9eb17bcd47a3f194a0f5bd7688141952be705909

Manifest digest:

sha256:bcce200e6df239646123383727ad513439c10c634b282ecdb073ab21ac5fe5b5

Size

9.99 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-portal:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-portal:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-portal@sha256:dccc5c85d5494cd6d3824c26ac32b25f871a43599f6ae91c21c33b1ae9ab76de
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-portal@sha256:cdb452d66c3a71b66f7eb39ec3d5a7884faaaa9e08501dfa9faa82fd729e19c3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-portal@sha256:496e6e5e007c88880bce6d1835dd7f8f4dc2399ca29a76a6ff363b2ef08cef6a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-portal@sha256:7793fc9fe461534e45a4bd20503440ed6f53b1397c55236e296053efa5284dee
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-portal@sha256:5805aa747e7e15e2cb6e77f7bd439d6d49b8a7e00b38f065a9a0b761cea353d2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-portal@sha256:f6cd82e807c7aa208475b91d1babab02a63b388297d1b4165f546f6b095ce30d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-portal@sha256:460d09489e202c39fb3a48927c0507f448c1f79dfaaa2c46bdcc54ec76938afe
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-portal@sha256:f99c2a476f635a66f791db0208ff3f053fe7c2b0622d3cca75d7b47e6ea594a1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-portal@sha256:66441ecb1a77e8a6e930e8c97cdf80677bd38e46204d4561b2bbf319ce84226b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-portal@sha256:60ac2ba100e32abd4462f518eb8ec296f6ab42f9028ee2e572e401c76c661034
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-portal@sha256:beff7e4457d878fffad1cc0537a0c2dbce0d1fb88c2b1d17e3e9e206cd9432d4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-portal@sha256:3071e6a386df53f5b23e1bce6f556e52a3b563907d4fb9e4f5f5e61111cecbd8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-portal@sha256:99cd97a0a15f98f75d62e7e17512f15e203d81030cbc656305c73051725a62cf
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-portal@sha256:d3a049e2272fbc6b4a8cd03f2279e51110817a035503e79f2901895577a5a360
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-portal@sha256:74874cdc971e12ad738b64841b4c690c056c26905923668d5e4640a25976f1ee