dhi.io/harbor-registryctl
2.12-debian-fips-dev, 2.12-debian13-fips-dev, 2.12-fips-dev, 2.12.4-debian-fips-dev, 2.12.4-debian13-fips-dev, 2.12.4-fips-dev
sha256:8ee5b0aed06e39a6f872d25445b5f335e0065a3b7605162ebe5bb719421eecaa
Manifest digest:sha256:6a34c328e85266116015f3a362067bc698cb563b8503c3926cec6454fc82d64e
Size
39.00 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/harbor-registryctl:2.12-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/harbor-registryctl:2.12-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/harbor-registryctl@sha256:9397d17fc3299e76397602de979570952524333540ab357b243db84e758042bc |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/harbor-registryctl@sha256:caf2e03f5ea692fb371327dbeb8ff07f519e32b8199fa825de6b504de4b41868 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/harbor-registryctl@sha256:11017d9405420e140fde18ee8c03c2100e836b78825c430919a6ed98c682c94c |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/harbor-registryctl@sha256:3879e98d297dfda0acb89dcd45701b8897690e2c7b5d0ba1e90cee5c3b45ee7e |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/harbor-registryctl@sha256:4c4f80421d87cd5c88ea08dc884435dc5e685b537a54f8f84d3db78eff614fbe |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/harbor-registryctl@sha256:45b8fc9732a27425723daf1ea927ee9557c82837ccc005b3e5ff018de62de090 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/harbor-registryctl@sha256:3a29e8b40785a3a31664a5900209c40895c3409916331c47eff3df216087c489 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/harbor-registryctl@sha256:aaafb30dd932c3d92f332ccef57449cf59336114793f95c325b5cc3caae1d17c |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/harbor-registryctl@sha256:406429e8ddbb6d328cee7756b5e6c75d154ab3fb3cbbfbace2928274f01d9804 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/harbor-registryctl@sha256:d6daa047db072df1a6f5dda96b13911371721b36d990ef398379bf0f858ecf02 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/harbor-registryctl@sha256:b9b89dcacc4ead7cc2fcbc1be1d8a60ca7b1a52a684cdf59b2695ace66babd08 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/harbor-registryctl@sha256:87fd6582bf06d823cf37df84d6e0a714216247601e9032f7bebe609a6c3c6974 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/harbor-registryctl@sha256:e9525164dccad4c5de6fcf85b2b49cf4b91fdfa0ac6f729d0167bae6e37143c5 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/harbor-registryctl@sha256:4227a3ec7c006bf0e03b6a7d02f23a30f7f6befe2f78d0dba40e6e619bf4f3e8 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/harbor-registryctl@sha256:360596a0062b5fb81bbebd316e238ba2d655f676998e92744745b8f9393ecaac |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/harbor-registryctl@sha256:3dce9e3a04684b6dd8a51e085cd218190d71d4f939e7502325d54f9e5a92fbb9 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/harbor-registryctl@sha256:39befcf8fde5f69ac33dc5deb884d8cbe0a6567b4b746109c95775d8c7118c9a |