dhi.io/harbor-registryctl
2.14-debian-dev, 2.14-debian13-dev, 2.14-dev, 2.14.4-debian-dev, 2.14.4-debian13-dev, 2.14.4-dev
sha256:dd32c9793d0ba8eb0c2081f05fc5fe74c3dae4f02dbd51cdb98ab70592c7b75f
Manifest digest:sha256:7b061d2ef7df4c4ea8fcc20d9547c4e03c6e9c4cdc3d2f0ef05541647032efd2
Size
38.26 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/harbor-registryctl:2.14-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/harbor-registryctl:2.14-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/harbor-registryctl@sha256:fe56291ea32e6288396599b5282d63e139d5823b73693d85a6065445300f0ba2 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/harbor-registryctl@sha256:7044ce0dd8961eeaf4334af254d131cc41aff612cd1deb976c5841eab54d7e6f |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/harbor-registryctl@sha256:7eea18ef9de83c441becaa6a508a7e38ac693383d006232ae103343800a8fbec |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/harbor-registryctl@sha256:10f9f3d22ddd8a1c18a97b4573d5b6026bcfed55440d15720c0fa033f4d28a3a |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/harbor-registryctl@sha256:03dabd5d3d67caecc63c769ae6ebdda1667ae04cef1fed4f36a3899b13e0f2fa |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/harbor-registryctl@sha256:c854c401b8b2e8d982c12de1977287f5e3ea8976032a2dcb5691be580a89e7c2 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/harbor-registryctl@sha256:696eb2e4c5cafdc8d5d1800b71aa222f719806f79b5c376a03961a541835a0b0 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/harbor-registryctl@sha256:c4ce7bf445e7c1428582fe5ea5597060c1d71b0d73d9a19399225e5f08b65f49 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/harbor-registryctl@sha256:4bb276aca659a296e7605bd15d09b664bc6a1c2e9a3c8512db88dbad7a13798d |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/harbor-registryctl@sha256:e4c9d062f77817443c6a6bacd70034db09aadf6bb8a14f9d1d597696d1173ff1 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/harbor-registryctl@sha256:4f1b47af3b8558801cb5d0df43b5604b07adc1d818141d3c97ed385f2e0c3b30 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/harbor-registryctl@sha256:3adb8c1b03564913993726d0eb139e272fd4fb4bedb74ea285c4f23a1c93d1d6 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/harbor-registryctl@sha256:9c457ac981e7b197b4fcda0fdb7048c8b2bded8298438f18ce6f7b22c98a73f8 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/harbor-registryctl@sha256:1e9022faa9e6d59ea7c3ad813e3521eff84b37e9defd4bb70c3f3f1c4a98e5c3 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/harbor-registryctl@sha256:786c5a9afef1912760fbbb81aee574d43b5d2b5aa16dc2fb5e1977c8b18d0351 |