dhi.io/harbor-registry
2.13-debian-fips-dev, 2.13-debian13-fips-dev, 2.13-fips-dev, 2.13.5-debian-fips-dev, 2.13.5-debian13-fips-dev, 2.13.5-fips-dev
sha256:448cbdb57268982b696a8d33fdd603679f4d5f378f202dfd6aaab74069d3afe5
Manifest digest:sha256:eecaabcc7bdede0cec310b8a8ed151e8a701b233104c53b5f637006b0f520289
Size
37.45 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/harbor-registry:2.13-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/harbor-registry:2.13-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/harbor-registry@sha256:e327aca0c696c522b88f7c623976e9375c76761fdf1c9a2fcbecf26b8de3569b |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/harbor-registry@sha256:dc6833223661188b89e298ee16cdc128f76eb6ba78caaa2706d06ebd8b8ae202 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/harbor-registry@sha256:95826610d93cf6fb3480d4fd8a05f2320772173fa1c473a22dcec3b0bffc7f12 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/harbor-registry@sha256:9908cf09237e31cedd2794bfb95bca7fe82fbc26c7c2bf5e06e3ed97c37ad37a |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/harbor-registry@sha256:ee13f2839d2b1183f8e896a1b55ce4a15773c096d952ad70660015d583111dcb |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/harbor-registry@sha256:b06fd6b9f63a07383f4ed41c34b2a0788a1ea2d4e69635e18e720be7e402cf44 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/harbor-registry@sha256:c1890efed392cc8cfc566ab4ac9610488f2ee94ac01d1e33de40184aeff1f139 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/harbor-registry@sha256:d123045bb5ce85cb79028d8a82ddfa9abf51f6b111c31760a7ba2256a40e5391 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/harbor-registry@sha256:a3c019626e13bb3e0ef78147c99bcda4b6d87c282daae9ba92cc3e422c931dd7 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/harbor-registry@sha256:5b76102fad431012067d87725ab3efc89cb006cc2a96348b06544a704b38e189 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/harbor-registry@sha256:233311ed1df610df711ac9dd1de3e93b98b60238c16041d208273a8d5f961016 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/harbor-registry@sha256:8d8c911b05fcb61b1330c503cbffb977d5f87d0546c8229a5f44df9322e36cc8 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/harbor-registry@sha256:a2273fd37e1fefad92179474cd130161e61f620d95730a616182f442b8933d28 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/harbor-registry@sha256:935c9575cbd7a2b25b7fdcd662d5241331a917b27ee67f61da650120efc9d9d6 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/harbor-registry@sha256:802d1710234bad3d103b55402668102eef95efb5929f9a12ecc5bd1f5b52423d |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/harbor-registry@sha256:13405543b8a9b5e1ccd04a28b6275d45d4b50abd2c1f0168ccb4bcdaf301f282 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/harbor-registry@sha256:1f8b9a948fa22fd8a6ad735493a0fd3a080a3ea4efd168ed32b9462f6be047ce |