Sign inSign up
Harbor Registry Control

dhi.io/harbor-registryctl

Harbor Registry Control 2.13.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.13-debian-fips, 2.13-debian13-fips, 2.13-fips, 2.13.5-debian-fips, 2.13.5-debian13-fips, 2.13.5-fips

Index digest:

sha256:8466b9646a0240d1b656fb7a4ba1e1ffb5e677c4fdfee45dd871e449c042c699

Manifest digest:

sha256:3b2abc821265bc699d045a3083dc6fc3de029cc0ba83a1827f872800913b4cbc

Size

16.98 MB

Last pushed

16 hours ago

Vulnerabilities

0
1
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-registryctl:2.13-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-registryctl:2.13-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-registryctl@sha256:dc9293540c182f582c5488ee791ea30b3165a2bb7e26324e3954cb777b114aea
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-registryctl@sha256:9d75fa22a0868145d22f3f8e86f3727bfc96270cec6f4ce4e465de607ebe6925
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-registryctl@sha256:f2c63a505edd6ca0e56bc7c3ff54eb549dd10569fc02a57997405f410d32de44
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-registryctl@sha256:9db6f8bc558ed50debc76e8e1fddf571d01a69e0d00cc28b8378fc88b57e99ef
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-registryctl@sha256:fd23902fd18633df53b542b4bedd315e62241c2181937039f43d1d44cc884c30
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-registryctl@sha256:13da371499b12808f534d6886142f3dcf1ab769d56d548e5c111eff803101b11
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-registryctl@sha256:dac44e7a40fc0e75a7bca525c3865b04a8a8bec3b76ebf23d143f01f5260c54c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-registryctl@sha256:8c539c94f3922879fb5e7396dfc52cfe72c27cd2bbf3743ba1ef0ae18b85500f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-registryctl@sha256:b7cbb11f1870ad1c822fa61ee83ae574d9d00e987502de5e3851f9765c3082bf
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-registryctl@sha256:f7c3c0674099e3a1408e9a532cb921b406b25d3fc315d35589f6ce55996db21f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-registryctl@sha256:5bf048036cf03d95b2b511ed41cff1dabcf0aa7dfdd5a34187befcf71a6cd3bc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-registryctl@sha256:a17f5f8ff87ecbd026f026ceea89b17909d7fa47e0aba608109e3306fef20340
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-registryctl@sha256:63d965e1fe19643adc60e6f07ee21d19636fbbeab5d96352a5f43ad320399cc9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-registryctl@sha256:4647a04691c45474c5a35f3bfdcc1d2d0170e59676d86fe815d77b45e09b8d2d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-registryctl@sha256:428074c2352867b0f190f089db91e05dc3bd65c26d673ae2bef3effc93999889
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-registryctl@sha256:78c34aad3d913610ba989e01cf86dffec314b81f9ac8915a20cff8af28adbf97
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-registryctl@sha256:05aba3fdd47a619947c09743abeae44a8bf4480816fb71702c5a338e873368f5