Sign inSign up
Harbor Registry

dhi.io/harbor-registry

Harbor Registry 2.13.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.13-debian-fips-dev, 2.13-debian13-fips-dev, 2.13-fips-dev, 2.13.5-debian-fips-dev, 2.13.5-debian13-fips-dev, 2.13.5-fips-dev

Index digest:

sha256:448cbdb57268982b696a8d33fdd603679f4d5f378f202dfd6aaab74069d3afe5

Manifest digest:

sha256:eecaabcc7bdede0cec310b8a8ed151e8a701b233104c53b5f637006b0f520289

Size

37.45 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-registry:2.13-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-registry:2.13-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-registry@sha256:e327aca0c696c522b88f7c623976e9375c76761fdf1c9a2fcbecf26b8de3569b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-registry@sha256:dc6833223661188b89e298ee16cdc128f76eb6ba78caaa2706d06ebd8b8ae202
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-registry@sha256:95826610d93cf6fb3480d4fd8a05f2320772173fa1c473a22dcec3b0bffc7f12
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-registry@sha256:9908cf09237e31cedd2794bfb95bca7fe82fbc26c7c2bf5e06e3ed97c37ad37a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-registry@sha256:ee13f2839d2b1183f8e896a1b55ce4a15773c096d952ad70660015d583111dcb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-registry@sha256:b06fd6b9f63a07383f4ed41c34b2a0788a1ea2d4e69635e18e720be7e402cf44
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-registry@sha256:c1890efed392cc8cfc566ab4ac9610488f2ee94ac01d1e33de40184aeff1f139
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-registry@sha256:d123045bb5ce85cb79028d8a82ddfa9abf51f6b111c31760a7ba2256a40e5391
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-registry@sha256:a3c019626e13bb3e0ef78147c99bcda4b6d87c282daae9ba92cc3e422c931dd7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-registry@sha256:5b76102fad431012067d87725ab3efc89cb006cc2a96348b06544a704b38e189
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-registry@sha256:233311ed1df610df711ac9dd1de3e93b98b60238c16041d208273a8d5f961016
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-registry@sha256:8d8c911b05fcb61b1330c503cbffb977d5f87d0546c8229a5f44df9322e36cc8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-registry@sha256:a2273fd37e1fefad92179474cd130161e61f620d95730a616182f442b8933d28
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-registry@sha256:935c9575cbd7a2b25b7fdcd662d5241331a917b27ee67f61da650120efc9d9d6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-registry@sha256:802d1710234bad3d103b55402668102eef95efb5929f9a12ecc5bd1f5b52423d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-registry@sha256:13405543b8a9b5e1ccd04a28b6275d45d4b50abd2c1f0168ccb4bcdaf301f282
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-registry@sha256:1f8b9a948fa22fd8a6ad735493a0fd3a080a3ea4efd168ed32b9462f6be047ce