dhi.io/harbor-registryctl
2.13-debian-dev, 2.13-debian13-dev, 2.13-dev, 2.13.5-debian-dev, 2.13.5-debian13-dev, 2.13.5-dev
sha256:49e5828812cd61008498ef279b0a587612f6da285809f01cfaa09d8cdf1341bd
Manifest digest:sha256:9ab918fbb89e1968a0b4eae59f6942a0e15bef69b8c1d831bd98ecf2fb991d58
Size
38.24 MB
Last pushed
1 hour ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/harbor-registryctl:2.13-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/harbor-registryctl:2.13-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/harbor-registryctl@sha256:9b6d363b0dfb518fd33127639f45d3128eee8780e73c9229b4e3517425b91fd4 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/harbor-registryctl@sha256:ea32dfdd44d163d17d4eb3eb79127751486f03dce603637f85cc48dc0f7149a5 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/harbor-registryctl@sha256:29d501f240b630bcfaa8c175af038277a7a6b4300b788c105962e113e7c4f1e1 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/harbor-registryctl@sha256:dbcd50b54a0ed4cadb7051ba597b02c39178199faf016326494e7fc40750041a |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/harbor-registryctl@sha256:81adb34c79f8e0dc881275469d64c573c909d5e77b04853a944c0f4b073058aa |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/harbor-registryctl@sha256:f23a954d090ba7190093f44c54c36e9d0d35d12a8e127985677afd6b8464634a |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/harbor-registryctl@sha256:9891c94e1d0927f0ac5b9d20eea4aebd78bfad9bb86e348ace9da5ac7efae0e5 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/harbor-registryctl@sha256:db2fa10f680d79a84f345fea30a5739e4dd02defce2aa3ccfa6de804d2d77011 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/harbor-registryctl@sha256:a43a766ef042c1437818da36f7e4e683aa8b097595d8f1bbd0abd391b18b6ac9 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/harbor-registryctl@sha256:2366f3fee3d890669522f3e8673c795efb12d6896bd1514434322bdb0dd280d1 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/harbor-registryctl@sha256:7bbb468a8c2e73bbf018e1b45734b6cb80cfb97d958bd0a0187e4fef2306f7c0 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/harbor-registryctl@sha256:a0ad15c1146997e14168a10ed8cc55cc739a97beafb28ae04dc67b9e3a0a44c6 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/harbor-registryctl@sha256:86cf2af44e9e6bde4e0b459ce44ce28ec1fab362ff6ea6ab6e7ac72d0c6db01e |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/harbor-registryctl@sha256:c721f05863a9346e40a29406014d7978b44af6efbbfb8685bc9a160ba1b5d05d |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/harbor-registryctl@sha256:c0bc299263441127b446a18e6fbf0ba58e43b27e81e86f418f8cbae403ba6032 |