Sign inSign up
Harbor Registry

dhi.io/harbor-registry

Harbor Registry 2.15.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips, 2-debian13-fips, 2-fips, 2.15-debian-fips, 2.15-debian13-fips, 2.15-fips, 2.15.2-debian-fips, 2.15.2-debian13-fips, 2.15.2-fips

Index digest:

sha256:d5a2fc905fefcbe114ab711cd3db8522e8fb56557c715857c7235d06216ce119

Manifest digest:

sha256:9521a1eaf35a78b4c3966cfd4fe18551cc84fdad0751a7fc318900d3377bd758

Size

15.96 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-registry:2-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-registry:2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-registry@sha256:285d1366f18c672bd3fec9c128526642651f02c2412088a250aff47f4566aea4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-registry@sha256:24c62b73f39c04c526d7427a0530ae2162267815830cdd9c1ce4bcba35046eba
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-registry@sha256:9f08bf49d2b475d06199bfa0d826cb8edb9f09cd5866cbbf9fd7c7710af8abf2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-registry@sha256:d8107f65e06e2301c25a8299a4786189e26a0d26dcd03157531cfba3673453b5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-registry@sha256:444b64145f87c387f13ab08addcba97c4bf8fd354fee8bee7a2d87201fc958a5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-registry@sha256:97817d977d95d6c73cf8960f5470b91f4043b4c2b5041fa4b14a30e5d263b057
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-registry@sha256:020a4701f258fb494294fd1f3685b9d2da37c7db02d80eabc1876aa4e8ca8022
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-registry@sha256:5e1f735e2bd2127abe251bb02b3a0c8a9ee82dbccdcadd0f4b688e39c3c01c4f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-registry@sha256:f832b7c2e15b6ba0c37d33dde86eea850ad7c4983afcaaabac27bbe5a72c0120
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-registry@sha256:b6868c0502ea828b4ca72c4bc2be2983efe8ca9fb2d61aae5e8c512e2e6f0896
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-registry@sha256:4b5febf646486bd14448b104c11de3d8dfe662afe0c49a519cc1faec5ca316f8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-registry@sha256:f92101611df03874da3acab0627934f8b19e0ef95e58c945a934a4d86689739c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-registry@sha256:a197d19a990736ce385e35812fd2e8d23d7036f7de643be0bf9b70c34bf930fa
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-registry@sha256:a26b1bb2c9a64008b185f6433bba11b762e7d6cd6be780145d0e7c49bb9be355
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-registry@sha256:0294b0db4d6dae78959db237c152d216f8bb2bd6c71f44ac153601ddc91e4fe5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-registry@sha256:818f80350fa79f6440b4a910182a88999e77f8792529968589f962cce65aaac5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-registry@sha256:10a4934811f988e5ddd695a2d0a28904c0e3d7425aee9cec9147779ad6e19a78