Sign inSign up
Harbor Registry Control

dhi.io/harbor-registryctl

Harbor Registry Control 2.13.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.13-debian-dev, 2.13-debian13-dev, 2.13-dev, 2.13.5-debian-dev, 2.13.5-debian13-dev, 2.13.5-dev

Index digest:

sha256:49e5828812cd61008498ef279b0a587612f6da285809f01cfaa09d8cdf1341bd

Manifest digest:

sha256:9ab918fbb89e1968a0b4eae59f6942a0e15bef69b8c1d831bd98ecf2fb991d58

Size

38.24 MB

Last pushed

1 hour ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-registryctl:2.13-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-registryctl:2.13-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-registryctl@sha256:9b6d363b0dfb518fd33127639f45d3128eee8780e73c9229b4e3517425b91fd4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-registryctl@sha256:ea32dfdd44d163d17d4eb3eb79127751486f03dce603637f85cc48dc0f7149a5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-registryctl@sha256:29d501f240b630bcfaa8c175af038277a7a6b4300b788c105962e113e7c4f1e1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-registryctl@sha256:dbcd50b54a0ed4cadb7051ba597b02c39178199faf016326494e7fc40750041a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-registryctl@sha256:81adb34c79f8e0dc881275469d64c573c909d5e77b04853a944c0f4b073058aa
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-registryctl@sha256:f23a954d090ba7190093f44c54c36e9d0d35d12a8e127985677afd6b8464634a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-registryctl@sha256:9891c94e1d0927f0ac5b9d20eea4aebd78bfad9bb86e348ace9da5ac7efae0e5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-registryctl@sha256:db2fa10f680d79a84f345fea30a5739e4dd02defce2aa3ccfa6de804d2d77011
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-registryctl@sha256:a43a766ef042c1437818da36f7e4e683aa8b097595d8f1bbd0abd391b18b6ac9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-registryctl@sha256:2366f3fee3d890669522f3e8673c795efb12d6896bd1514434322bdb0dd280d1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-registryctl@sha256:7bbb468a8c2e73bbf018e1b45734b6cb80cfb97d958bd0a0187e4fef2306f7c0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-registryctl@sha256:a0ad15c1146997e14168a10ed8cc55cc739a97beafb28ae04dc67b9e3a0a44c6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-registryctl@sha256:86cf2af44e9e6bde4e0b459ce44ce28ec1fab362ff6ea6ab6e7ac72d0c6db01e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-registryctl@sha256:c721f05863a9346e40a29406014d7978b44af6efbbfb8685bc9a160ba1b5d05d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-registryctl@sha256:c0bc299263441127b446a18e6fbf0ba58e43b27e81e86f418f8cbae403ba6032